The BullGuard products and services are part of NortonLifeLock Inc., a global leader in consumer Cyber Safety with a portofolio of brands including Norton, Avira and more. Learn more at NortonLifeLock.com

Not sure I am rid of virus

Posted 9/5/2009 4:09 PM
#76978
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
I seem to have/had new folder exe virus. I followed advice you gave to another forum post, downloading the Fix folder, including CCleaner, MalawarebytesAM, Combofix and Hijack This (having previously tried to use SDFix but it wouldn't open). When I clicked on CCleaner it also wouldn't open, so I could not run it. I ran MalawarebytesAM which dealt with 30+ infected files but said that 2 files could not be cleaned & it was set to do it on reboot. I restarted and ran Malaware again, this time there was 1 file that couldn't be cleaned & it gave the same message. After restarting, I thought I'd run Malaware again but now it will not open (I have shut down & restarted several times). Also when I reopened the Fix folder, CCleaner icon has disappeared. Believeing there to still be a problem, I ran Combofix. I did not run Hijack this as I did not understand the instructions of what it would do (afraid I am not techie). On a side note, it is now possible to open SDFix, but again, I don't understand fully how to operate it.

I have a few questions: First, how should I check if my laptop is now virus free, or how shall I proceed otherwise?
Second, this virus (new folder exe, preventing files from opening) is also on 2 USB memory sticks & (more alarmingly) my digital camera SD Memory Card. Can I plug these into the laptop to clean them with one of these programmes? They contain data that I have not had a chance to store elsewhere.

Thank you in advance for your help!
Posted 9/5/2009 8:18 PM
#76983
User avatar

Jintan Advanced member

Date Joined Nov 2016
Total Posts: 1049
Welcome to BullGuard forums sarahviajera,


Sounds like a newer and pesky "user mode rootkit" had been active there. Let's get some details and see what might still need to be done there.


To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.


Download RSIT (random's system information tool) from here to your desktop, then click on the RSIT.exe to start the scan.

If necessary allow it to locate or download a copy of HijackThis as needed.

Once the scan completes a textbox will open - copy/paste those contents here for review please. The log can also be found at C:\rsit\log.txt.

RSIT will also create a second log, info.txt, which will be minimized to your taskbar. Post that here as well please (it will also be stored at C:\rsit\info.txt).

You can break logs into parts and use separate posts here when replying and posting the log files, if needed.

--------------

Also click here and download the installer for Gmer to your desktop, then click that file to run Gmer.


If on it's opening scan Gmer locates items shown in red or indicates "hidden" or "rootkit", stop there, and click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please. We don't want any crashes just from taking an initial look at things.

If not, then click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan).

When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.
Posted 9/6/2009 3:31 AM
#77007
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
Thank you. I am going to try this but probably don't have time to run it until tomorrow. Should I put my infected memory card in the card reader while I run this program you have suggested?
Posted 9/6/2009 7:25 PM
#77055
User avatar

Jintan Advanced member

Date Joined Nov 2016
Total Posts: 1049
No rush - we will do repairs once logs are posted back here. If the memory card has a file system you can view using Explorer (right click My Computer, left click Explore) then yes, insert that before moving forward.
Posted 9/11/2009 7:23 PM
#77305
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
I ran RSIT. Here is the log and info txts created.

file of random's system information tool 1.06 (written by random/random)
Run by a at 2009-09-12 00:48:56
Microsoft Windows XP Professional Service Pack 2
System drive C: has 151 MB (1%) free of 15 GB
Total RAM: 1014 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:00 AM, on 9/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\scvhost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\XP-0AA2FAD2.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\Msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\scvhost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\DOCUME~1\a\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\9W-7A730.EXE
C:\DOCUME~1\a\LOCALS~1\Temp\jcelpw.exe
C:\DOCUME~1\a\LOCALS~1\Temp\winblvgwy.exe
C:\DOCUME~1\a\LOCALS~1\Temp\w458ab.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\a\My Documents\Downloads\RSIT.exe
C:\Documents and Settings\a\Desktop\FIX\a.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: Shell=Explorer.exe scvhost.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [XP-0AA2FAD2] C:\WINDOWS\system32\XP-0AA2FAD2.EXE
O4 - HKLM\..\Run: [SYS1] C:\WINDOWS\system32\system.exe
O4 - HKLM\..\Run: [SYS2] C:\WINDOWS\system32\bad1.exe
O4 - HKLM\..\Run: [SYS3] C:\WINDOWS\system32\bad2.exe
O4 - HKLM\..\Run: [SYS4] C:\WINDOWS\system32\bad3.exe
O4 - HKLM\..\Run: [Msmsgs] C:\WINDOWS\system32\Msmsgs.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\scvhost.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\scvhost.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\scvhost.exe (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Startup: ¡¡¡¡¡¡.lnk = C:\WINDOWS\system32\XP-0AA2FAD2.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 6418 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\At1.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-27 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-08-27 761840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-08-27 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-27 256112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-12-27 18081280]
"AzMixerSel"=C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe [2006-01-26 122880]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-28 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-28 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-28 137752]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-11-21 1471784]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-27 487424]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 113520]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-07-13 292128]
"XP-0AA2FAD2"=C:\WINDOWS\system32\XP-0AA2FAD2.EXE [2009-09-05 1512476]
"SYS1"=C:\WINDOWS\system32\system.exe []
"SYS2"=C:\WINDOWS\system32\bad1.exe [2009-09-05 65]
"SYS3"=C:\WINDOWS\system32\bad2.exe [2009-09-05 65]
"SYS4"=C:\WINDOWS\system32\bad3.exe [2009-09-05 65]
"Msmsgs"=C:\WINDOWS\system32\Msmsgs.exe [2008-01-24 285184]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-04 1667584]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-06-16 39408]
"Yahoo Messengger"=C:\WINDOWS\system32\scvhost.exe [2009-01-27 1247963]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Documents and Settings\a\Start Menu\Programs\Startup
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
¡¡¡¡¡¡.lnk - C:\WINDOWS\system32\XP-0AA2FAD2.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=91
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoFind"=1
"NoFolderOptions"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\SimpChinese\setup.exe"="C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\SimpChinese\setup.exe:*:Enabled:????????? 2009 Setup"
"C:\WINDOWS\ALCMTR.EXE"="C:\WINDOWS\ALCMTR.EXE:*:Enabled:ipsec"
"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe:*:Enabled:ipsec"
"C:\WINDOWS\RTHDCPL.EXE"="C:\WINDOWS\RTHDCPL.EXE:*:Enabled:ipsec"
"C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe"="C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wscntfy.exe"="C:\WINDOWS\system32\wscntfy.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\igfxtray.exe"="C:\WINDOWS\system32\igfxtray.exe:*:Enabled:ipsec"
"C:\Program Files\Windows Media Player\wmplayer.exe"="C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\cleanmgr.exe"="C:\WINDOWS\system32\cleanmgr.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wuauclt.exe"="C:\WINDOWS\system32\wuauclt.exe:*:Enabled:ipsec"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\iTunes\iTunesHelper.exe"="C:\Program Files\iTunes\iTunesHelper.exe:*:Enabled:ipsec"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe:*:Enabled:ipsec"
"C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe"="C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe:*:Enabled:ipsec"
"C:\Program Files\QuickTime\QTTask.exe"="C:\Program Files\QuickTime\QTTask.exe:*:Enabled:ipsec"
"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"="C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE:*:Enabled:ipsec"
"C:\WINDOWS\system32\cmd.exe"="C:\WINDOWS\system32\cmd.exe:*:Enabled:ipsec"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\at.exe"="C:\WINDOWS\system32\at.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\igfxpers.exe"="C:\WINDOWS\system32\igfxpers.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\igfxsrvc.exe"="C:\WINDOWS\system32\igfxsrvc.exe:*:Enabled:ipsec"
"D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE"="D:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE:*:Enabled:ipsec"
"C:\WINDOWS\system32\CF25750.exe"="C:\WINDOWS\system32\CF25750.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\jdfouv.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\jdfouv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winghnp.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winghnp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winqwkk.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winqwkk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\w41d96.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\w41d96.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\windsnr.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\windsnr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winpwylg.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winpwylg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winybdmm.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winybdmm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winjvpgc.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winjvpgc.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\qqfu.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\qqfu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winoubdlf.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winoubdlf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\wintsjhrb.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\wintsjhrb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\vixm.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\vixm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winiefrf.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winiefrf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winymgb.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winymgb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winmxscue.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winmxscue.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\wwcdwm.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\wwcdwm.exe:*:Enabled:ipsec"
"G:\system.exe"="G:\system.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.exe"="C:\WINDOWS\Explorer.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\userinit.exe"="C:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\windjcwn.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\windjcwn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\tkvwx.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\tkvwx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winxufbyp.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winxufbyp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\w4ae5d.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\w4ae5d.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winnpgqw.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winnpgqw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\sanlii.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\sanlii.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winxilyg.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winxilyg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\w4e79d.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\w4e79d.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winoqps.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winoqps.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winjgsl.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winjgsl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winggwra.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winggwra.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\wincbupgq.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\wincbupgq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winemjdef.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winemjdef.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\gsay.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\gsay.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\windrdvj.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\windrdvj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\suhse.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\suhse.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winpfkylo.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winpfkylo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\raulqj.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\raulqj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winyqwtm.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winyqwtm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winlscp.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winlscp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\idsjy.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\idsjy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winuaik.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winuaik.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winnmgl.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winnmgl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winqjps.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winqjps.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\rbirt.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\rbirt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\oshgm.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\oshgm.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\scvhost.exe"="C:\WINDOWS\system32\scvhost.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winudor.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winudor.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winxnjbty.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winxnjbty.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\lhri.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\lhri.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\w49d84.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\w49d84.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winucssn.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winucssn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winujjk.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winujjk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\w3d737.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\w3d737.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winfjvwqt.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winfjvwqt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\nkijbe.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\nkijbe.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\uudquo.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\uudquo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\oppge.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\oppge.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\pefs.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\pefs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\bskhso.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\bskhso.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\eqhmra.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\eqhmra.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winyprvbp.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winyprvbp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winvdvnyk.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winvdvnyk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winkiict.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winkiict.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\w40b37.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\w40b37.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\Msmsgs.exe"="C:\WINDOWS\system32\Msmsgs.exe:*:Enabled:ipsec"
"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"="C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winrxtllh.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winrxtllh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\gfrp.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\gfrp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winxefccg.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winxefccg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\w41fc9.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\w41fc9.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winwrfrx.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winwrfrx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\xlkmb.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\xlkmb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\winscyjhk.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\winscyjhk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\wmrv.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\wmrv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\a\LOCALS~1\Temp\riqcld.exe"="C:\DOCUME~1\a\LOCALS~1\Temp\riqcld.exe:*:Enabled:ipsec"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 3 months======

2009-09-12 00:48:56 ----D---- C:\rsit
2009-09-11 15:28:39 ----A---- C:\WINDOWS\system32\9W-7A730.EXE
2009-09-11 15:28:38 ----SH---- C:\WINDOWS\system32\69a8c2.exe
2009-09-05 22:41:56 ----RASH---- C:\WINDOWS\system32\setting.ini
2009-09-05 22:39:58 ----RASH---- C:\WINDOWS\system32\autorun.ini
2009-09-05 22:39:57 ----RASH---- C:\WINDOWS\system32\scvhost.exe
2009-09-05 22:39:57 ----RASH---- C:\WINDOWS\system32\blastclnnn.exe
2009-09-05 22:39:57 ----A---- C:\WINDOWS\scvhost.exe
2009-09-05 22:37:05 ----A---- C:\WINDOWS\system32\bad3.exe
2009-09-05 22:37:04 ----A---- C:\WINDOWS\system32\bad2.exe
2009-09-05 22:37:04 ----A---- C:\WINDOWS\system32\bad1.exe
2009-09-05 22:37:03 ----RASH---- C:\WINDOWS\system32\msmsgs.exe
2009-09-05 22:24:10 ----SHD---- C:\RECYCLER
2009-09-05 22:21:43 ----A---- C:\WINDOWS\system32\a7.ini
2009-09-05 22:21:42 ----SH---- C:\WINDOWS\system32\7a9cd3.exe
2009-09-05 22:21:42 ----A---- C:\WINDOWS\system32\8X-E0925.EXE
2009-09-05 22:19:23 ----RSH---- C:\WINDOWS\system32\XP-0AA2FAD2.EXE
2009-09-05 22:19:23 ----ASH---- C:\WINDOWS\system32\ul.dll
2009-09-05 22:19:23 ----ASH---- C:\WINDOWS\system32\og.dll
2009-09-05 21:20:32 ----D---- C:\WINDOWS\temp
2009-09-05 21:20:30 ----A---- C:\ComboFix.txt
2009-09-05 21:12:17 ----A---- C:\Boot.bak
2009-09-05 21:12:12 ----RASHD---- C:\cmdcons
2009-09-05 21:08:53 ----A---- C:\WINDOWS\zip.exe
2009-09-05 21:08:53 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-09-05 21:08:53 ----A---- C:\WINDOWS\SWSC.exe
2009-09-05 21:08:53 ----A---- C:\WINDOWS\SWREG.exe
2009-09-05 21:08:53 ----A---- C:\WINDOWS\sed.exe
2009-09-05 21:08:53 ----A---- C:\WINDOWS\PEV.exe
2009-09-05 21:08:53 ----A---- C:\WINDOWS\NIRCMD.exe
2009-09-05 21:08:53 ----A---- C:\WINDOWS\grep.exe
2009-09-05 21:08:46 ----D---- C:\WINDOWS\ERDNT
2009-09-05 21:08:21 ----D---- C:\Qoobox
2009-09-05 19:33:53 ----D---- C:\Documents and Settings\a\Application Data\Malwarebytes
2009-09-05 19:33:47 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-09-05 19:33:47 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-08-28 16:50:24 ----D---- C:\SDFix
2009-08-27 22:26:48 ----D---- C:\Documents and Settings\a\Application Data\Mozilla
2009-08-27 22:26:33 ----D---- C:\Program Files\Mozilla Firefox
2009-08-23 17:02:31 ----D---- C:\Program Files\iPod
2009-08-23 17:02:26 ----D---- C:\Program Files\iTunes
2009-08-17 18:07:36 ----D---- C:\WINDOWS\system32\VirtualExpander
2009-07-13 22:28:51 ----A---- C:\WINDOWS\system32\HX-2579E.EXE
2009-07-13 22:28:50 ----SH---- C:\WINDOWS\system32\vt-7326.exe
2009-07-06 21:39:04 ----A---- C:\WINDOWS\system32\a5.ini
2009-07-06 21:39:02 ----SH---- C:\WINDOWS\system32\vt-7626.exe
2009-07-06 21:39:02 ----A---- C:\WINDOWS\system32\HV-D5E54.EXE
2009-07-02 08:45:07 ----D---- C:\Documents and Settings\a\Application Data\U3
2009-06-16 23:18:53 ----AC---- C:\WINDOWS\system32\ptpusb.dll
2009-06-16 23:18:52 ----A---- C:\WINDOWS\system32\ptpusd.dll
2009-06-16 14:08:54 ----D---- C:\Program Files\Common Files\Adobe
2009-06-16 13:25:50 ----D---- C:\Documents and Settings\a\Application Data\Google
2009-06-16 13:11:42 ----D---- C:\Program Files\Adobe
2009-06-16 13:11:26 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-06-16 13:11:24 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-06-16 13:08:51 ----D---- C:\Program Files\Google
2009-06-16 13:08:51 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-06-16 13:06:31 ----D---- C:\Program Files\NOS
2009-06-16 13:06:31 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-06-16 11:09:06 ----D---- C:\Documents and Settings\a\Application Data\Media Player Classic
2009-06-16 10:49:50 ----AC---- C:\WINDOWS\system32\chtbrkr.dll
2009-06-16 10:49:50 ----AC---- C:\WINDOWS\system32\chsbrkr.dll
2009-06-16 10:49:49 ----AC---- C:\WINDOWS\system32\msir3jp.dll
2009-06-16 10:49:49 ----AC---- C:\WINDOWS\system32\korwbrkr.dll
2009-06-16 10:49:31 ----AC---- C:\WINDOWS\system32\c_g18030.dll
2009-06-16 10:49:30 ----AC---- C:\WINDOWS\system32\kbd101a.dll
2009-06-16 10:49:18 ----AC---- C:\WINDOWS\system32\kbdnecNT.dll
2009-06-16 10:49:18 ----AC---- C:\WINDOWS\system32\kbdnecAT.dll
2009-06-16 10:49:18 ----AC---- C:\WINDOWS\system32\kbdnec95.dll
2009-06-16 10:49:18 ----AC---- C:\WINDOWS\system32\kbdlk41j.dll
2009-06-16 10:49:18 ----AC---- C:\WINDOWS\system32\kbdlk41a.dll
2009-06-16 10:49:17 ----AC---- C:\WINDOWS\system32\kbdibm02.dll
2009-06-16 10:49:17 ----AC---- C:\WINDOWS\system32\kbdax2.dll
2009-06-16 10:49:17 ----AC---- C:\WINDOWS\system32\kbd106n.dll
2009-06-16 10:49:17 ----AC---- C:\WINDOWS\system32\kbd101.dll
2009-06-16 10:49:17 ----AC---- C:\WINDOWS\system32\f3ahvoas.dll
2009-06-16 10:48:54 ----AC---- C:\WINDOWS\system32\c_is2022.dll
2009-06-16 10:48:50 ----AC---- C:\WINDOWS\system32\uniime.dll
2009-06-16 10:48:43 ----AC---- C:\WINDOWS\system32\imjp81k.dll
2009-06-16 10:39:49 ----AC---- C:\WINDOWS\system32\kbdkor.dll
2009-06-16 10:39:49 ----AC---- C:\WINDOWS\system32\kbdjpn.dll
2009-06-16 10:39:49 ----AC---- C:\WINDOWS\system32\kbd106.dll
2009-06-16 10:39:49 ----AC---- C:\WINDOWS\system32\kbd103.dll
2009-06-16 10:39:49 ----AC---- C:\WINDOWS\system32\kbd101c.dll
2009-06-16 10:39:45 ----AC---- C:\WINDOWS\system32\kbd101b.dll
2009-06-16 10:39:28 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-16 10:31:13 ----AC---- C:\WINDOWS\ODBC.INI
2009-06-16 10:31:09 ----A---- C:\WINDOWS\system32\mdimon.dll
2009-06-16 10:30:01 ----D---- C:\Program Files\Microsoft ActiveSync
2009-06-16 10:29:57 ----D---- C:\Program Files\Common Files\DESIGNER
2009-06-16 10:29:40 ----D---- C:\WINDOWS\SHELLNEW
2009-06-16 09:19:06 ----A---- C:\WINDOWS\system32\igfxres.dll
2009-06-16 09:17:04 ----D---- C:\WINDOWS\system32\Atheros_L1e
2009-06-16 09:16:24 ----C---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2009-06-16 09:16:20 ----HDC---- C:\WINDOWS\$NtUninstallWdf01007$
2009-06-16 09:16:14 ----D---- C:\Program Files\Synaptics
2009-06-16 09:16:12 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-06-16 09:16:04 ----AC---- C:\WINDOWS\system32\WdfCoInstaller01007.dll
2009-06-16 09:16:04 ----AC---- C:\WINDOWS\system32\SynTPCo4.dll
2009-06-16 09:16:04 ----AC---- C:\WINDOWS\system32\SynCtrl.dll
2009-06-16 09:16:04 ----A---- C:\WINDOWS\system32\SynTPAPI.dll
2009-06-16 09:16:04 ----A---- C:\WINDOWS\system32\SynCOM.dll
2009-06-16 09:15:40 ----D---- C:\Program Files\Intel
2009-06-16 09:15:11 ----A---- C:\WINDOWS\system32\hidserv.dll
2009-06-16 09:15:07 ----D---- C:\WINDOWS\Options
2009-06-16 09:15:07 ----D---- C:\Program Files\Atheros
2009-06-16 09:15:01 ----D---- C:\temp
2009-06-16 09:14:54 ----D---- C:\Documents and Settings\All Users\Application Data\Atheros
2009-06-16 09:14:53 ----D---- C:\Documents and Settings\a\Application Data\InstallShield
2009-06-16 09:14:25 ----AC---- C:\WINDOWS\system32\RTS5121icon.dll
2009-06-16 09:14:12 ----AC---- C:\WINDOWS\system32\rts5121.dll
2009-06-16 09:12:48 ----AC---- C:\WINDOWS\system32\btw_ci.dll
2009-06-16 09:12:41 ----D---- C:\Program Files\WIDCOMM
2009-06-16 09:11:29 ----AC---- C:\WINDOWS\system32\igldev32.dll
2009-06-16 09:11:29 ----AC---- C:\WINDOWS\system32\igfxext.exe
2009-06-16 09:11:29 ----AC---- C:\WINDOWS\system32\igfxexps.dll
2009-06-16 09:11:29 ----A---- C:\WINDOWS\system32\igxprd32.dll
2009-06-16 09:11:29 ----A---- C:\WINDOWS\system32\igxpdv32.dll
2009-06-16 09:11:29 ----A---- C:\WINDOWS\system32\igfxtray.exe
2009-06-16 09:11:29 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2009-06-16 09:11:29 ----A---- C:\WINDOWS\system32\igfxpers.exe
2009-06-16 09:11:29 ----A---- C:\WINDOWS\system32\hccutils.dll
2009-06-16 09:11:28 ----AC---- C:\WINDOWS\system32\iglicd32.dll
2009-06-16 09:11:28 ----AC---- C:\WINDOWS\system32\igfxzoom.exe
2009-06-16 09:11:28 ----AC---- C:\WINDOWS\system32\igfxdo.dll
2009-06-16 09:11:28 ----AC---- C:\WINDOWS\system32\igfxCoIn_v4926.dll
2009-06-16 09:11:28 ----AC---- C:\WINDOWS\system32\igfxcfg.exe
2009-06-16 09:11:28 ----A---- C:\WINDOWS\system32\igxpgd32.dll
2009-06-16 09:11:28 ----A---- C:\WINDOWS\system32\igxpdx32.dll
2009-06-16 09:11:28 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2009-06-16 09:11:28 ----A---- C:\WINDOWS\system32\igfxress.dll
2009-06-16 09:11:28 ----A---- C:\WINDOWS\system32\igfxpph.dll
2009-06-16 09:11:28 ----A---- C:\WINDOWS\system32\igfxdev.dll
2009-06-16 09:11:28 ----A---- C:\WINDOWS\system32\hkcmd.exe
2009-06-16 09:11:27 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-06-16 09:11:27 ----D---- C:\WINDOWS\system32\Lang
2009-06-16 09:11:27 ----AC---- C:\WINDOWS\system32\igxpun.exe
2009-06-16 09:11:27 ----AC---- C:\WINDOWS\system32\difxapi.dll
2009-06-16 09:11:23 ----D---- C:\Intel
2009-06-16 09:10:25 ----D---- C:\WINDOWS\system32\RTCOM
2009-06-16 09:09:41 ----AC---- C:\WINDOWS\system32\spupdsvc.exe
2009-06-16 09:09:40 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2009-06-16 09:09:37 ----AC---- C:\WINDOWS\vncutil.exe
2009-06-16 09:09:37 ----AC---- C:\WINDOWS\SOUNDMAN.EXE
2009-06-16 09:09:37 ----AC---- C:\WINDOWS\SkyTel.exe
2009-06-16 09:09:36 ----AC---- C:\WINDOWS\system32\RtkCoInstXP.dll
2009-06-16 09:09:36 ----AC---- C:\WINDOWS\RtlUpd.exe
2009-06-16 09:09:36 ----AC---- C:\WINDOWS\RTLCPL.EXE
2009-06-16 09:09:36 ----AC---- C:\WINDOWS\RtkAudioService.exe
2009-06-16 09:09:35 ----A---- C:\WINDOWS\RTHDCPL.EXE
2009-06-16 09:09:34 ----D---- C:\Program Files\Realtek
2009-06-16 09:09:34 ----AC---- C:\WINDOWS\MicCal.exe
2009-06-16 09:09:34 ----AC---- C:\WINDOWS\ALCWZRD.EXE
2009-06-16 09:09:34 ----A---- C:\WINDOWS\ALCMTR.EXE
2009-06-16 09:09:33 ----HD---- C:\Program Files\InstallShield Installation Information
2009-06-16 09:09:29 ----AC---- C:\WINDOWS\RtlExUpd.dll
2009-06-16 09:09:24 ----D---- C:\Program Files\Common Files\InstallShield
2009-06-16 09:09:11 ----D---- C:\Documents and Settings\a\Application Data\WinRAR
2009-06-16 09:09:03 ----D---- C:\Program Files\WinRAR
2009-06-16 09:02:55 ----D---- C:\a
2009-06-16 08:58:06 ----D---- C:\Documents and Settings\a\Application Data\Identities
2009-06-16 08:58:03 ----HD---- C:\Program Files\Uninstall Information
2009-06-16 08:57:54 ----ASH---- C:\Documents and Settings\a\Application Data\desktop.ini
2009-06-16 08:57:53 ----SD---- C:\Documents and Settings\a\Application Data\Microsoft
2009-06-16 08:57:19 ----D---- C:\WINDOWS\SoftwareDistribution
2009-06-16 08:57:16 ----D---- C:\WINDOWS\Prefetch
2009-06-16 08:57:15 ----SD---- C:\WINDOWS\system32\Microsoft
2009-06-16 08:57:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-06-16 08:52:56 ----D---- C:\WINDOWS\system32\xircom
2009-06-16 08:52:56 ----D---- C:\Program Files\xerox
2009-06-16 08:52:56 ----D---- C:\Program Files\microsoft frontpage
2009-06-16 08:52:25 ----AC---- C:\WINDOWS\control.ini
2009-06-16 08:52:25 ----A---- C:\AUTOEXEC.BAT
2009-06-16 08:52:11 ----AC---- C:\WINDOWS\OEWABLog.txt
2009-06-16 08:52:06 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-06-16 08:50:56 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-06-16 08:50:56 ----RD---- C:\WINDOWS\Offline Web Pages
2009-06-16 08:50:56 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-06-16 08:50:47 ----RAHC---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-06-16 08:50:40 ----HD---- C:\Program Files\WindowsUpdate
2009-06-16 08:50:16 ----D---- C:\WINDOWS\system32\DirectX
2009-06-16 08:49:54 ----AC---- C:\WINDOWS\system32\atrace.dll
2009-06-16 08:49:51 ----AC---- C:\WINDOWS\system32\desktop.ini
2009-06-16 08:49:51 ----AC---- C:\WINDOWS\desktop.ini
2009-06-16 08:49:44 ----AC---- C:\WINDOWS\system32\nmevtmsg.dll
2009-06-16 08:49:43 ----A---- C:\WINDOWS\system32\acctres.dll
2009-06-16 08:49:42 ----D---- C:\Program Files\Common Files\Services
2009-06-16 08:49:40 ----SD---- C:\WINDOWS\Tasks
2009-06-16 08:49:40 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-06-16 08:49:39 ----D---- C:\Program Files\Common Files\MSSoap
2009-06-16 08:49:35 ----D---- C:\WINDOWS\srchasst
2009-06-16 08:49:34 ----D---- C:\WINDOWS\system32\Macromed
2009-06-16 08:49:31 ----AC---- C:\WINDOWS\system32\wuweb.dll
2009-06-16 08:49:31 ----AC---- C:\WINDOWS\system32\wucltui.dll
2009-06-16 08:49:31 ----AC---- C:\WINDOWS\system32\wuaueng1.dll
2009-06-16 08:49:31 ----A---- C:\WINDOWS\system32\wups.dll
2009-06-16 08:49:31 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-06-16 08:49:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-06-16 08:49:30 ----N---- C:\WINDOWS\system32\wuauclt.exe
2009-06-16 08:49:30 ----C---- C:\WINDOWS\system32\qmgr.dll
2009-06-16 08:49:30 ----AC---- C:\WINDOWS\system32\wuauclt1.exe
2009-06-16 08:49:30 ----AC---- C:\WINDOWS\system32\qmgrprxy.dll
2009-06-16 08:49:30 ----AC---- C:\WINDOWS\system32\bitsprx3.dll
2009-06-16 08:49:30 ----AC---- C:\WINDOWS\system32\bitsprx2.dll
2009-06-16 08:49:30 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-06-16 08:49:26 ----D---- C:\Program Files\Movie Maker
2009-06-16 08:49:22 ----AC---- C:\WINDOWS\system32\safrslv.dll
2009-06-16 08:49:22 ----AC---- C:\WINDOWS\system32\safrdm.dll
2009-06-16 08:49:22 ----AC---- C:\WINDOWS\system32\safrcdlg.dll
2009-06-16 08:49:22 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-06-16 08:49:19 ----AC---- C:\WINDOWS\system32\fltMc.exe
2009-06-16 08:49:19 ----AC---- C:\WINDOWS\system32\fltlib.dll
2009-06-16 08:49:18 ----N---- C:\WINDOWS\system32\srsvc.dll
2009-06-16 08:49:18 ----D---- C:\WINDOWS\system32\Restore
2009-06-16 08:49:18 ----AC---- C:\WINDOWS\system32\srrstr.dll
2009-06-16 08:49:18 ----A---- C:\WINDOWS\system32\srclient.dll
2009-06-16 08:49:17 ----AC---- C:\WINDOWS\system32\nmmkcert.dll
2009-06-16 08:49:17 ----AC---- C:\WINDOWS\system32\msconf.dll
2009-06-16 08:49:17 ----AC---- C:\WINDOWS\system32\mnmsrvc.exe
2009-06-16 08:49:17 ----AC---- C:\WINDOWS\system32\mnmdd.dll
2009-06-16 08:49:17 ----AC---- C:\WINDOWS\system32\isrdbg32.dll
2009-06-16 08:49:17 ----AC---- C:\WINDOWS\system32\ils.dll
2009-06-16 08:49:14 ----D---- C:\Program Files\NetMeeting
2009-06-16 08:49:14 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-06-16 08:49:14 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-06-16 08:49:13 ----A---- C:\WINDOWS\system32\inetres.dll
2009-06-16 08:49:13 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-06-16 08:49:11 ----N---- C:\WINDOWS\system32\schedsvc.dll
2009-06-16 08:49:11 ----D---- C:\Program Files\Outlook Express
2009-06-16 08:49:11 ----AC---- C:\WINDOWS\system32\mstinit.exe
2009-06-16 08:49:11 ----A---- C:\WINDOWS\system32\mstask.dll
2009-06-16 08:49:10 ----AC---- C:\WINDOWS\system32\isign32.dll
2009-06-16 08:49:10 ----AC---- C:\WINDOWS\system32\icwphbk.dll
2009-06-16 08:49:10 ----AC---- C:\WINDOWS\system32\icwdial.dll
2009-06-16 08:49:10 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-06-16 08:49:04 ----D---- C:\Program Files\Common Files\System
2009-06-16 08:49:01 ----D---- C:\Program Files\Internet Explorer
2009-06-16 08:48:13 ----D---- C:\Program Files\ComPlus Applications
2009-06-16 08:48:11 ----AC---- C:\WINDOWS\vbaddin.ini
2009-06-16 08:48:11 ----AC---- C:\WINDOWS\vb.ini
2009-06-16 08:48:05 ----D---- C:\WINDOWS\Registration
2009-06-16 08:47:55 ----D---- C:\Program Files\Windows Media Player
2009-06-16 08:47:55 ----D---- C:\Program Files\Online Services
2009-06-16 08:47:48 ----D---- C:\Program Files\Messenger
2009-06-16 08:47:44 ----D---- C:\Program Files\MSN Gaming Zone
2009-06-16 08:47:44 ----AC---- C:\WINDOWS\system32\write.exe
2009-06-16 08:47:34 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-06-16 08:47:33 ----AC---- C:\WINDOWS\system32\hticons.dll
2009-06-16 08:47:33 ----AC---- C:\WINDOWS\system32\avwav.dll
2009-06-16 08:47:33 ----AC---- C:\WINDOWS\system32\avtapi.dll
2009-06-16 08:47:33 ----AC---- C:\WINDOWS\system32\avmeter.dll
2009-06-16 08:47:32 ----AC---- C:\WINDOWS\system32\winchat.exe
2009-06-16 08:47:25 ----AC---- C:\WINDOWS\system32\getuname.dll
2009-06-16 08:47:25 ----AC---- C:\WINDOWS\system32\charmap.exe
2009-06-16 08:47:25 ----AC---- C:\WINDOWS\system32\calc.exe
2009-06-16 08:47:24 ----AC---- C:\WINDOWS\system32\sol.exe
2009-06-16 08:47:24 ----AC---- C:\WINDOWS\system32\mshearts.exe
2009-06-16 08:47:24 ----AC---- C:\WINDOWS\system32\freecell.exe
2009-06-16 08:47:24 ----A---- C:\WINDOWS\system32\winmine.exe
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\usrlogon.cmd
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\tsshutdn.exe
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\tslabels.ini
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\tskill.exe
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\tsdiscon.exe
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\tscon.exe
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\shadow.exe
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\rwinsta.exe
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\reset.exe
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\regini.exe
2009-06-16 08:47:23 ----AC---- C:\WINDOWS\system32\rdpcfgex.dll
2009-06-16 08:47:22 ----AC---- C:\WINDOWS\system32\qwinsta.exe
2009-06-16 08:47:22 ----AC---- C:\WINDOWS\system32\qappsrv.exe
2009-06-16 08:47:22 ----AC---- C:\WINDOWS\system32\msg.exe
2009-06-16 08:47:22 ----AC---- C:\WINDOWS\system32\msdtcprf.ini
2009-06-16 08:47:22 ----AC---- C:\WINDOWS\system32\logoff.exe
2009-06-16 08:47:22 ----AC---- C:\WINDOWS\system32\cdmodem.dll
2009-06-16 08:47:21 ----AC---- C:\WINDOWS\system32\mtxlegih.dll
2009-06-16 08:47:21 ----AC---- C:\WINDOWS\system32\mtxex.dll
2009-06-16 08:47:21 ----AC---- C:\WINDOWS\system32\mtxdm.dll
2009-06-16 08:47:21 ----AC---- C:\WINDOWS\system32\dcomcnfg.exe
2009-06-16 08:47:21 ----AC---- C:\WINDOWS\system32\comrepl.dll
2009-06-16 08:47:21 ----AC---- C:\WINDOWS\system32\comaddin.dll
2009-06-16 08:47:20 ----AC---- C:\WINDOWS\system32\stclient.dll
2009-06-16 08:47:20 ----AC---- C:\WINDOWS\system32\comsnap.dll
2009-06-16 08:47:15 ----AC---- C:\WINDOWS\system32\wmimgmt.msc
2009-06-16 08:47:04 ----D---- C:\Program Files\MSN
2009-06-16 08:47:03 ----AC---- C:\WINDOWS\system32\sndrec32.exe
2009-06-16 08:47:03 ----AC---- C:\WINDOWS\system32\mplay32.exe
2009-06-16 08:47:03 ----AC---- C:\WINDOWS\system32\hypertrm.dll
2009-06-16 08:47:03 ----AC---- C:\WINDOWS\system32\accwiz.exe
2009-06-16 08:47:02 ----D---- C:\Program Files\Windows NT
2009-06-16 08:47:02 ----AC---- C:\WINDOWS\system32\spider.exe
2009-06-16 08:47:02 ----AC---- C:\WINDOWS\system32\clipbrd.exe
2009-06-16 08:47:02 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-06-16 08:47:01 ----AC---- C:\WINDOWS\system32\tscfgwmi.dll
2009-06-16 08:47:01 ----AC---- C:\WINDOWS\system32\sessmgr.exe
2009-06-16 08:47:01 ----AC---- C:\WINDOWS\system32\remotepg.dll
2009-06-16 08:47:01 ----AC---- C:\WINDOWS\system32\rdshost.exe
2009-06-16 08:47:01 ----AC---- C:\WINDOWS\system32\rdsaddin.exe
2009-06-16 08:47:01 ----AC---- C:\WINDOWS\system32\mstscax.dll
2009-06-16 08:47:01 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-06-16 08:47:00 ----N---- C:\WINDOWS\system32\termsrv.dll
2009-06-16 08:47:00 ----AC---- C:\WINDOWS\system32\tscupgrd.exe
2009-06-16 08:47:00 ----AC---- C:\WINDOWS\system32\rdpwsx.dll
2009-06-16 08:47:00 ----AC---- C:\WINDOWS\system32\rdpsnd.dll
2009-06-16 08:47:00 ----AC---- C:\WINDOWS\system32\rdpclip.exe
2009-06-16 08:47:00 ----AC---- C:\WINDOWS\system32\rdchost.dll
2009-06-16 08:47:00 ----AC---- C:\WINDOWS\system32\qprocess.exe
2009-06-16 08:47:00 ----AC---- C:\WINDOWS\system32\cfgbkend.dll
2009-06-16 08:47:00 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-06-16 08:46:59 ----D---- C:\WINDOWS\system32\MsDtc
2009-06-16 08:46:59 ----AC---- C:\WINDOWS\system32\xolehlp.dll
2009-06-16 08:46:59 ----AC---- C:\WINDOWS\system32\mtxoci.dll
2009-06-16 08:46:59 ----AC---- C:\WINDOWS\system32\msdtcuiu.dll
2009-06-16 08:46:59 ----AC---- C:\WINDOWS\system32\msdtctm.dll
2009-06-16 08:46:59 ----AC---- C:\WINDOWS\system32\msdtcprx.dll
2009-06-16 08:46:58 ----D---- C:\WINDOWS\system32\Com
2009-06-16 08:46:58 ----AC---- C:\WINDOWS\system32\msdtclog.dll
2009-06-16 08:46:58 ----AC---- C:\WINDOWS\system32\msdtc.exe
2009-06-16 08:46:58 ----AC---- C:\WINDOWS\system32\catsrvps.dll
2009-06-16 08:46:58 ----A---- C:\WINDOWS\system32\colbact.dll
2009-06-16 08:46:57 ----AC---- C:\WINDOWS\system32\clbcatex.dll
2009-06-16 08:46:57 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-06-16 08:46:57 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-06-16 08:46:57 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-06-16 08:46:56 ----AC---- C:\WINDOWS\system32\comuid.dll
2009-06-16 08:46:56 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-06-16 08:46:50 ----AC---- C:\WINDOWS\system32\servdeps.dll
2009-06-16 08:46:49 ----AC---- C:\WINDOWS\system32\mmfutil.dll
2009-06-16 08:46:49 ----AC---- C:\WINDOWS\system32\licwmi.dll
2009-06-16 08:46:49 ----AC---- C:\WINDOWS\system32\cmprops.dll
2009-06-16 01:45:37 ----A---- C:\WINDOWS\system32\h323log.txt
2009-06-16 01:44:12 ----AC---- C:\WINDOWS\system32\vfwwdm32.dll
2009-06-16 01:44:12 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-06-16 01:42:47 ----A---- C:\WINDOWS\system32\usbui.dll
2009-06-16 01:41:10 ----AC---- C:\WINDOWS\imsins.BAK
2009-06-16 01:41:06 ----SHD---- C:\WINDOWS\Installer
2009-06-16 01:41:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-06-16 01:41:05 ----D---- C:\Program Files\Common Files\ODBC
2009-06-16 01:41:05 ----AC---- C:\WINDOWS\ODBCINST.INI
2009-06-16 01:41:01 ----RD---- C:\Program Files
2009-06-16 01:41:01 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-06-16 01:41:01 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-06-16 01:41:01 ----D---- C:\Program Files\Common Files
2009-06-16 01:40:57 ----RAC---- C:\WINDOWS\system32\kbdtuq.dll
2009-06-16 01:40:57 ----RAC---- C:\WINDOWS\system32\kbdtuf.dll
2009-06-16 01:40:57 ----RAC---- C:\WINDOWS\system32\kbdazel.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdycc.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbduzb.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdur.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdtat.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdru1.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdru.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdmon.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdkyr.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdkaz.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdbu.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdblr.dll
2009-06-16 01:40:54 ----RAC---- C:\WINDOWS\system32\kbdaze.dll
2009-06-16 01:40:52 ----RAC---- C:\WINDOWS\system32\kbdhept.dll
2009-06-16 01:40:52 ----RAC---- C:\WINDOWS\system32\kbdhela3.dll
2009-06-16 01:40:52 ----RAC---- C:\WINDOWS\system32\kbdhela2.dll
2009-06-16 01:40:52 ----RAC---- C:\WINDOWS\system32\kbdhe319.dll
2009-06-16 01:40:52 ----RAC---- C:\WINDOWS\system32\kbdhe220.dll
2009-06-16 01:40:52 ----RAC---- C:\WINDOWS\system32\kbdhe.dll
2009-06-16 01:40:52 ----RAC---- C:\WINDOWS\system32\kbdgkl.dll
2009-06-16 01:40:50 ----RAC---- C:\WINDOWS\system32\kbdlv1.dll
2009-06-16 01:40:50 ----RAC---- C:\WINDOWS\system32\kbdlv.dll
2009-06-16 01:40:50 ----RAC---- C:\WINDOWS\system32\kbdlt1.dll
2009-06-16 01:40:50 ----RAC---- C:\WINDOWS\system32\kbdlt.dll
2009-06-16 01:40:50 ----RAC---- C:\WINDOWS\system32\kbdest.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdycl.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdsl1.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdsl.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdro.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdpl1.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdpl.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdhu1.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdhu.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdcz2.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdcz1.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdcz.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\kbdcr.dll
2009-06-16 01:40:47 ----RAC---- C:\WINDOWS\system32\KBDAL.DLL
2009-06-16 01:40:43 ----AC---- C:\WINDOWS\system32\spxcoins.dll
2009-06-16 01:40:43 ----AC---- C:\WINDOWS\system32\irclass.dll
2009-06-16 01:40:43 ----AC---- C:\WINDOWS\system32\EqnClass.Dll
2009-06-16 01:40:43 ----AC---- C:\WINDOWS\system32\dgsetup.dll
2009-06-16 01:40:43 ----AC---- C:\WINDOWS\system32\dgrpsetu.dll
2009-06-16 01:40:40 ----C---- C:\WINDOWS\system32\CONFIG.TMP
2009-06-16 01:40:40 ----AC---- C:\WINDOWS\TASKMAN.EXE
2009-06-16 01:40:40 ----AC---- C:\WINDOWS\system32\batt.dll
2009-06-16 01:40:39 ----AC---- C:\WINDOWS\NOTEPAD.EXE
2009-06-16 01:40:38 ----A---- C:\WINDOWS\system32\storprop.dll
2009-06-16 01:40:26 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-06-16 01:40:21 ----RAC---- C:\WINDOWS\SET8.tmp
2009-06-16 01:40:17 ----RAC---- C:\WINDOWS\SET4.tmp
2009-06-16 01:40:16 ----RAC---- C:\WINDOWS\SET3.tmp
2009-06-16 01:40:10 ----D---- C:\WINDOWS\system32\CatRoot2
2009-06-16 01:40:10 ----D---- C:\WINDOWS\system32\CatRoot
2009-06-16 01:40:04 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-06-16 01:39:39 ----SHD---- C:\System Volume Information
2009-06-16 01:39:39 ----D---- C:\Documents and Settings
2009-06-16 01:39:08 ----RASH---- C:\boot.ini
2009-06-16 01:31:58 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-06-16 01:31:58 ----RSD---- C:\WINDOWS\Fonts
2009-06-16 01:31:58 ----RD---- C:\WINDOWS\Web
2009-06-16 01:31:58 ----HD---- C:\WINDOWS\inf
2009-06-16 01:31:58 ----D---- C:\WINDOWS\WinSxS
2009-06-16 01:31:58 ----D---- C:\WINDOWS\twain_32
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\wins
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\wbem
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\usmt
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\spool
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\ShellExt
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\Setup
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\ras
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\oobe
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\npp
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\mui
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\inetsrv
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\IME
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\icsxml
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\ias
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\export
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\drivers
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\dhcp
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\config
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\3com_dmi
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\3076
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\2052
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\1054
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\1042
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\1041
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\1037
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\1033
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\1031
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\1028
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32\1025
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system32
2009-06-16 01:31:58 ----D---- C:\WINDOWS\system
2009-06-16 01:31:58 ----D---- C:\WINDOWS\security
2009-06-16 01:31:58 ----D---- C:\WINDOWS\Resources
2009-06-16 01:31:58 ----D---- C:\WINDOWS\repair
2009-06-16 01:31:58 ----D---- C:\WINDOWS\Provisioning
2009-06-16 01:31:58 ----D---- C:\WINDOWS\PeerNet
2009-06-16 01:31:58 ----D---- C:\WINDOWS\pchealth
2009-06-16 01:31:58 ----D---- C:\WINDOWS\mui
2009-06-16 01:31:58 ----D---- C:\WINDOWS\msapps
2009-06-16 01:31:58 ----D---- C:\WINDOWS\msagent
2009-06-16 01:31:58 ----D---- C:\WINDOWS\Media
2009-06-16 01:31:58 ----D---- C:\WINDOWS\java
2009-06-16 01:31:58 ----D---- C:\WINDOWS\ime
2009-06-16 01:31:58 ----D---- C:\WINDOWS\Help
2009-06-16 01:31:58 ----D---- C:\WINDOWS\ehome
2009-06-16 01:31:58 ----D---- C:\WINDOWS\Driver Cache
2009-06-16 01:31:58 ----D---- C:\WINDOWS\Debug
2009-06-16 01:31:58 ----D---- C:\WINDOWS\Cursors
2009-06-16 01:31:58 ----D---- C:\WINDOWS\Connection Wizard
2009-06-16 01:31:58 ----D---- C:\WINDOWS\Config
2009-06-16 01:31:58 ----D---- C:\WINDOWS\AppPatch
2009-06-16 01:31:58 ----D---- C:\WINDOWS\addins
2009-06-16 01:31:58 ----D---- C:\WINDOWS
2009-06-15 20:59:02 ----D---- C:\Documents and Settings\a\Application Data\Adobe
2009-06-15 20:56:47 ----D---- C:\Documents and Settings\a\Application Data\Macromedia
2009-06-15 19:36:04 ----D---- C:\Documents and Settings\a\Application Data\Apple Computer
2009-06-15 19:35:57 ----AC---- C:\WINDOWS\system32\GEARAspi.dll
2009-06-15 19:35:38 ----D---- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-15 19:35:22 ----D---- C:\Program Files\Bonjour
2009-06-15 19:34:43 ----D---- C:\Program Files\QuickTime
2009-06-15 19:34:41 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2009-06-15 19:34:17 ----D---- C:\Program Files\Apple Software Update
2009-06-15 19:34:09 ----A---- C:\WINDOWS\system32\usbaaplrc.dll
2009-06-15 19:33:30 ----D---- C:\Program Files\Common Files\Apple
2009-06-15 19:33:30 ----D---- C:\Documents and Settings\All Users\Application Data\Apple

======List of files/folders modified in the last 3 months======

2009-09-05 21:18:43 ----A---- C:\WINDOWS\system.ini
2009-06-16 12:44:04 ----AC---- C:\WINDOWS\explorer.exe
2009-06-16 08:52:25 ----A---- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2008-08-15 1318464]
R3 asc3360pr;asc3360pr; \??\C:\WINDOWS\system32\drivers\kklqfg.sys []
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2007-03-23 37424]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2007-11-06 879528]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-04 14080]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-08 138752]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-12-27 4968448]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-09-24 38400]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-11-21 204464]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-28 503008]
S3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2007-11-06 539576]
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2007-06-30 156392]
S3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys [2007-04-01 55352]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2007-08-28 74656]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-20 23400]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RTS5121.sys [2008-11-22 160256]
S3 Rts516xIR;Realtek IR Driver; C:\WINDOWS\system32\DRIVERS\Rts516xIR.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-06-06 39424]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\WINDOWS\system32\DRIVERS\Rts5161ccid.sys []
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-06-06 144712]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2007-11-02 264800]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-07-13 542496]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2009-06-04 66048]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-16 264688]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 162864]

-----------------EOF-----------------

info.txt logfile of random's system information tool 1.06 2009-09-12 00:49:04

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->MsiExec.exe /X{6D8D64BE-F500-55B6-705D-DFD08AFE0624}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Download Manager-->"C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Apple Mobile Device Support-->MsiExec.exe /I{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver-->"C:\Program Files\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe" -runfromtemp -l0x0009 -removeonly
Atheros for Acer Driver v7.6.0.260_Foxconn Installation Program-->C:\Program Files\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-49B25D32EB33}\setup.exe -runfromtemp -l0x0009 -removeonly
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\a\Desktop\FIX\HijackThis.exe" /uninstall
Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
iTunes-->MsiExec.exe /I{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7-->"C:\WINDOWS\$NtUninstallWdf01007$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Mozilla Firefox (3.5.2)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
USB2.0 Card Reader Software-->"C:\Program Files\InstallShield Installation Information\{96AE7E41-E34E-47D0-AC07-1091A8127911}\setup.exe" -runfromtemp -l0x0009 -removeonly
WIDCOMM Bluetooth Software-->MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe

======System event log======

Computer Name: A-9A2981E268A44
Event Code: 14103
Message: QoS [Adapter {5FFCD301-939C-4B7F-BC7E-FF3166F2FACA}]:
The netcard driver failed the query for OID_GEN_LINK_SPEED.

Record Number: 4527
Source Name: PSched
Time Written: 20090727193901.000000+330
Event Type: error
User:

Computer Name: A-9A2981E268A44
Event Code: 1005
Message: Your computer has detected that the IP address 192.168.0.161 for the Network Card
with network address 00235A546328 is already in use on the network.
Your computer will automatically attempt to obtain a different address.

Record Number: 4526
Source Name: Dhcp
Time Written: 20090727193748.000000+330
Event Type: warning
User:

Computer Name: A-9A2981E268A44
Event Code: 4198
Message: The system detected an address conflict for IP address 192.168.0.161 with the system
having network hardware address 00:1E:8C:A1:14:48. The local interface has been disabled.

Record Number: 4523
Source Name: Tcpip
Time Written: 20090727193728.000000+330
Event Type: error
User:

Computer Name: A-9A2981E268A44
Event Code: 4198
Message: The system detected an address conflict for IP address 192.168.0.161 with the system
having network hardware address 00:1E:8C:A1:14:48. The local interface has been disabled.

Record Number: 4519
Source Name: Tcpip
Time Written: 20090727193329.000000+330
Event Type: error
User:

Computer Name: A-9A2981E268A44
Event Code: 4307
Message: Initialization failed because the transport refused to open initial Addresses.

Record Number: 4518
Source Name: NetBT
Time Written: 20090727193229.000000+330
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 28 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=1c02
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

-----------------EOF-----------------
Posted 9/12/2009 11:14 PM
#77329
User avatar

Jintan Advanced member

Date Joined Nov 2016
Total Posts: 1049
A messy Sality variant infection there, and from other thread experience with it it adds it's code to some files so it gets recreated during reboots.


Open Notepad (Start, Run type notepad and select Enter) and copy/paste the following text (inside the Code box).

[CODE][Version]
Signature="$CHICAGO$"

[DefaultInstall]
DelReg=Del.Settings

[Del.Settings]
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableTaskMgr
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\explorer,NoFolderOptions[/CODE]

Save this as correct.inf

Where it says "Files of Type", select All Files and click on Save and save it to your desktop. Exit Notepad, Then right-click on correct.inf and select Install. That is intended to return Task Manager and some other functions. If at any time the infection blocks these again while we do repairs just "Install" this correct.inf again.

-----------------

Open HijackThis, and choose None of the above, just start the program. Click Config – Misc Tools – Open process manager. From the list, click each of the following if it is present, and Kill Process. Close HijackThis. The file names may appear different there, but be sure to kill anything running from a Temp folder.

C:\WINDOWS\system32\9W-7A730.EXE
C:\DOCUME~1\a\LOCALS~1\Temp\jcelpw.exe
C:\DOCUME~1\a\LOCALS~1\Temp\winblvgwy.exe
C:\DOCUME~1\a\LOCALS~1\Temp\w458ab.exe


-----------------

You have a slightly older version of ComboFix there, by the looks of the log info. This updates very regularly, so delete any existing copies of ComboFix.exe, a download ComboFix.exe from here to your desktop, but I would like you to rename the file as you download it (do not download it directly without renaming it - use right click "Save Target/Link As" ). For this, rename the downloading file to 456out.com, then click the renamed 456out.com to run that scan.

Be sure to install the Recovery Console if you are asked to do so. When the scan completes, a text window with your log will open. Please copy and paste that log back here.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.
Posted 9/14/2009 5:08 PM
#77379
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
hello

I have followed the last instructions, although I'm not entirely sure I killed all relevant processes. Definitely did the ones that matched list plus other similar from temp files. Here is the Combofix log:

ComboFix 09-09-14.01 - a 09/14/2009 22:27.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.526 [GMT 5.5:30]
Running from: c:\documents and settings\a\My Documents\Downloads\456out.com.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\a\LOCALS~1\Temp\E_4
c:\docume~1\a\LOCALS~1\Temp\E_4\com.run
c:\docume~1\a\LOCALS~1\Temp\E_4\dp1.fne
c:\docume~1\a\LOCALS~1\Temp\E_4\eAPI.fne
c:\docume~1\a\LOCALS~1\Temp\E_4\internet.fne
c:\docume~1\a\LOCALS~1\Temp\E_4\krnln.fnr
c:\docume~1\a\LOCALS~1\Temp\E_4\RegEx.fnr
c:\docume~1\a\LOCALS~1\Temp\E_4\shell.fne
c:\docume~1\a\LOCALS~1\Temp\E_4\spec.fne
c:\documents and settings\a\Start Menu\Programs\Startup\¡¡¡¡¡¡.lnk
c:\windows\autorun.inf
c:\windows\hinhem.scr
c:\windows\scvhost.exe
c:\windows\system32\autorun.ini
c:\windows\system32\bad1.exe
c:\windows\system32\bad2.exe
c:\windows\system32\bad3.exe
c:\windows\system32\blastclnnn.exe
c:\windows\system32\com.run
c:\windows\system32\dp1.fne
c:\windows\system32\eAPI.fne
c:\windows\system32\internet.fne
c:\windows\system32\krnln.fnr
c:\windows\system32\msmsgs.exe
c:\windows\system32\og.dll
c:\windows\system32\og.edt
c:\windows\system32\RegEx.fnr
c:\windows\system32\scvhost.exe
c:\windows\system32\setting.ini
c:\windows\system32\shell.fne
c:\windows\system32\spec.fne
c:\windows\system32\ul.dll
c:\windows\system32\XP-0AA2FAD2.EXE

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ASC3360PR
-------\Service_asc3360pr


((((((((((((((((((((((((( Files Created from 2009-08-14 to 2009-09-14 )))))))))))))))))))))))))))))))
.

2009-09-14 16:02 . 2009-09-14 16:02 22016 ----a-w- c:\windows\system32\7G-C2E36.EXE
2009-09-14 16:02 . 2009-09-14 16:02 22016 --sh--w- c:\windows\system32\F62C71.EXE
2009-09-11 19:18 . 2009-09-11 19:19 -------- d-----w- C:\rsit
2009-09-11 09:58 . 2009-09-14 15:55 21504 ----a-w- c:\windows\system32\9W-7A730.EXE
2009-09-11 09:58 . 2009-09-11 09:58 21504 --sh--w- c:\windows\system32\69a8c2.exe
2009-09-05 16:51 . 2009-09-11 09:00 20992 ----a-w- c:\windows\system32\8X-E0925.EXE
2009-09-05 16:51 . 2009-09-05 16:51 20992 --sh--w- c:\windows\system32\7a9cd3.exe
2009-09-05 14:03 . 2009-09-05 14:03 -------- d-----w- c:\documents and settings\a\Application Data\Malwarebytes
2009-09-05 14:03 . 2009-08-03 08:06 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-05 14:03 . 2009-09-05 14:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-05 14:03 . 2009-09-05 14:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-05 14:03 . 2009-08-03 08:06 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-28 11:20 . 2009-09-05 15:55 -------- d-----w- C:\SDFix
2009-08-27 16:56 . 2009-08-27 16:56 0 ----a-w- c:\windows\nsreg.dat
2009-08-27 16:56 . 2009-08-27 16:56 -------- d-----w- c:\documents and settings\a\Local Settings\Application Data\Mozilla
2009-08-27 12:28 . 2009-08-27 12:28 -------- d-----w- c:\documents and settings\a\Bluetooth Software
2009-08-23 11:32 . 2009-08-23 11:32 -------- d-----w- c:\program files\iPod
2009-08-23 11:32 . 2009-08-23 11:32 -------- d-----w- c:\program files\iTunes
2009-08-20 10:38 . 2001-08-17 08:32 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-08-20 10:38 . 2001-08-17 08:32 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-08-17 12:37 . 2009-08-17 12:37 -------- d-----w- c:\windows\system32\VirtualExpander

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-23 12:19 . 2009-07-02 03:15 -------- d-----w- c:\documents and settings\a\Application Data\U3
2009-08-23 11:32 . 2009-06-15 14:03 -------- d-----w- c:\program files\Common Files\Apple
2009-07-27 06:30 . 2009-07-13 16:58 20480 ----a-w- c:\windows\system32\HX-2579E.EXE
2009-07-13 16:58 . 2009-07-13 16:58 20480 --sh--w- c:\windows\system32\vt-7326.exe
2009-07-13 12:48 . 2009-07-06 16:09 20480 ----a-w- c:\windows\system32\HV-D5E54.EXE
2009-07-06 16:09 . 2009-07-06 16:09 20480 --sh--w- c:\windows\system32\vt-7626.exe
.

------- Sigcheck -------

[-] 2009-06-16 . 8B9B057BCD245AF49C26463A3EEC93FB . 1032192 . . [6.00.2900.2180] . . c:\windows\explorer.exe
[-] 2009-06-16 . 8B9B057BCD245AF49C26463A3EEC93FB . 1032192 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-09-05_15.48.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 12:00 . 2009-09-05 15:38 40394 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-09-14 16:14 40394 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-09-14 16:14 312172 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2009-09-05 15:38 312172 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2009-08-17 12:37 73728 ----a-w- c:\windows\system32\VirtualExpander\VEShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-16 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-01-26 122880]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-11-21 1471784]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 487424]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 113520]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-12-26 18081280]

c:\documents and settings\a\Start Menu\Programs\Startup\
VirtualExpander.lnk - c:\windows\system32\VirtualExpander\VirtualExpander.exe [2009-8-17 430080]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-11-2 576104]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\SimpChinese\\setup.exe"=
"c:\\WINDOWS\\ALCMTR.EXE"=
"c:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe"=
"c:\\WINDOWS\\RTHDCPL.EXE"=
"c:\\Program Files\\Realtek\\Audio\\Drivers\\AzMixerSel.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\WINDOWS\\system32\\cleanmgr.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\iTunes\\iTunesHelper.exe"=
"c:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"=
"c:\\Program Files\\Adobe\\Reader 9.0\\Reader\\AcroRd32.exe"=
"c:\\Program Files\\QuickTime\\QTTask.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE"=
"c:\\WINDOWS\\system32\\cmd.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\at.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"d:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=

R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [6/16/2009 9:16 AM 38400]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [6/16/2009 1:06 PM 66048]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [6/16/2009 9:14 AM 160256]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - ASC3360PR
.
Contents of the 'Scheduled Tasks' folder

2009-06-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\a\Application Data\Mozilla\Firefox\Profiles\pjujlvr0.default\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-XP-0AA2FAD2 - c:\windows\system32\XP-0AA2FAD2.EXE
HKU-Default-Run-Yahoo Messengger - c:\windows\system32\scvhost.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2009-09-14 22:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3476)
c:\windows\system32\VirtualExpander\VEShellExt.dll
c:\windows\system32\btmmhook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\iPod\bin\iPodService.exe
c:\docume~1\a\LOCALS~1\temp\RtkBtMnt.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-14 22:35 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-14 17:05
ComboFix2.txt 2009-09-05 15:50

Pre-Run: 1,462,816,768 bytes free
Post-Run: 1,463,660,544 bytes free

202
Posted 9/15/2009 2:50 AM
#77390
User avatar

Jintan Advanced member

Date Joined Nov 2016
Total Posts: 1049
Progress, but it looks like explorer.exe has been altered or replaced there. We will need to correct that before making our next moves.


Go to Start > Run and type:

cmd.exe

and ok. Copy and paste the below string after the prompt, then press Enter >

dir /s /a "c:\*explorer*.*" > c:\find.txt && notepad c:\find.txt

Your drive will be scanned and when finished, Notepad will pop up with some information. Copy and paste it in this thread please.

Once that Notepad textbox opens, also click at the prompt in the still open command console window and type exit to close that.
Posted 9/15/2009 6:20 AM
#77392
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
I couldn't get your string to paste in but I typed it & it seemed to work. Here's the log: (by the way, is this internet explorer that has a problem? i dont' use it at all , only firefox - shall i delete the programme?)

Volume in drive C has no label.
Volume Serial Number is 3420-3DA0

Directory of c:\Documents and Settings\a\Application Data\Microsoft

06/16/2009 08:58 AM Internet Explorer
0 File(s) 0 bytes

Directory of c:\Documents and Settings\a\Application Data\Microsoft\Internet Explorer\Quick Launch

06/16/2009 08:58 AM 779 Launch Internet Explorer Browser.lnk
1 File(s) 779 bytes

Directory of c:\Documents and Settings\a\Local Settings\Application Data\Microsoft

06/15/2009 06:39 PM Internet Explorer
0 File(s) 0 bytes

Directory of c:\Documents and Settings\a\Start Menu\Programs

06/16/2009 08:58 AM 767 Internet Explorer.lnk
1 File(s) 767 bytes

Directory of c:\Documents and Settings\a\Start Menu\Programs\Accessories

06/16/2009 08:50 AM 1,487 Windows Explorer.lnk
1 File(s) 1,487 bytes

Directory of c:\Documents and Settings\Default User\Application Data\Microsoft

06/16/2009 08:52 AM Internet Explorer
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Default User\Start Menu\Programs\Accessories

06/16/2009 08:50 AM 1,487 Windows Explorer.lnk
1 File(s) 1,487 bytes

Directory of c:\Documents and Settings\LocalService\Application Data\Microsoft

06/16/2009 08:52 AM Internet Explorer
0 File(s) 0 bytes

Directory of c:\Documents and Settings\NetworkService\Application Data\Microsoft

06/16/2009 08:52 AM Internet Explorer
0 File(s) 0 bytes

Directory of c:\Program Files

06/16/2009 08:50 AM Internet Explorer
0 File(s) 0 bytes

Directory of c:\Program Files\Online Services

06/16/2009 08:47 AM 1,798 Use MSN Explorer to sign up for Internet Access (US only).lnk
1 File(s) 1,798 bytes

Directory of c:\Program Files\WIDCOMM\Bluetooth Software

11/02/2007 05:25 AM 125,480 btsendto_explorer.exe
1 File(s) 125,480 bytes

Directory of c:\WINDOWS

06/16/2009 12:44 PM 1,032,192 explorer.exe
08/04/2004 05:30 PM 80 explorer.scf
2 File(s) 1,032,272 bytes

Directory of c:\WINDOWS\Prefetch

09/14/2009 10:34 PM 74,358 EXPLORER.EXE-082F38A9.pf
1 File(s) 74,358 bytes

Directory of c:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft

06/16/2009 08:51 AM Internet Explorer
0 File(s) 0 bytes

Directory of c:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories

06/16/2009 08:50 AM 1,487 Windows Explorer.lnk
1 File(s) 1,487 bytes

Directory of c:\WINDOWS\system32\dllcache

06/16/2009 12:44 PM 1,032,192 explorer.exe
1 File(s) 1,032,192 bytes

Total Files Listed:
11 File(s) 2,272,107 bytes
7 Dir(s) 1,297,715,200 bytes free
Posted 9/15/2009 4:13 PM
#77397
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
The laptop seems to be behaving now - I don't get invalid messages when I boot up and windows operations seem to be functioning normally, and I don't see any more 'new folder' folders. My big concern now is how to get the virus (new folder) off my SD memory card. The laptop has an internal card reader & the photos show as files, however, I cannot open any of the memory card files and it is driving me crazy. Can you suggest what software I can use to clean it? I'm afraid of deleting my pictures by mistake.

By the way, thank you for all your help so far!!
Posted 9/16/2009 12:04 AM
#77402
User avatar

Jintan Advanced member

Date Joined Nov 2016
Total Posts: 1049
No, the target is what runs your desktop (among other tasks), explorer.exe. The date and size seem okay, but a thing called an "MD5 hash mark" for it is undocumented. Our goal here is to remove all infection from all parts of the system, as well as make everything right again.


Make sure you can [URL="https://www.cybertechhelp.com/tutorial/article/how-to-show-hidden-files"]View Hidden Files[/URL]. Also uncheck "Hide Extensions for Known File Types"

Then go here, press new topic, fill in the needed details and just give a link to your post back here (see the "Instructions for uploading files" there for help, if needed). Then press the browse button and then navigate to & select the following file on your computer.

c:\windows\explorer.exe

You DO NOT need to be a member to upload, anybody can upload the files. You will not be able to see the file once uploaded.

----------------

Be sure to continue to temporarily disable any protective software when running the scan tools we use here.


Open notepad (go to Start, Run, type notepad and press Enter) and copy/paste the text in the codebox below into it:

[code]KillAll::
File::
c:\windows\system32\7G-C2E36.EXE
c:\windows\system32\F62C71.EXE
c:\windows\system32\9W-7A730.EXE
c:\windows\system32\69a8c2.exe
c:\windows\system32\8X-E0925.EXE
c:\windows\system32\7a9cd3.exe
c:\windows\system32\HX-2579E.EXE
c:\windows\system32\vt-7326.exe
c:\windows\system32\HV-D5E54.EXE
c:\windows\system32\vt-7626.exe [/code]
Save this to your desktop as CFScript.txt


You should now have both ComboFix and that CFScript.txt on the desktop. Just left click/hold on the CFScript.txt file, and drag it into ComboFix to start the scan.

ComboFix will now run as it did before. Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

-------------

Open and update Malwarebytes.

* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform quick scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
* The log is automatically saved by Malwarebytes and can be viewed by clicking the Logs tab in Malwarebytes.
* Copy and Paste the entire report in your next reply. If it calls for a reboot to complete the repairs do that as well then.

-------

Post that log and the C:\ComboFix.txt log please.
Posted 9/16/2009 5:10 PM
#77434
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
Combofix & malawarebytes run. here are the logs. Malaware detected a worm that it said the computer needed to be rebooted to delete - i will do this but don't know how to confirm it has been deleted on reboot.

ComboFix 09-09-14.01 - a 09/16/2009 21:50.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.581 [GMT 5.5:30]
Running from: c:\documents and settings\a\My Documents\Downloads\456out.com.exe
Command switches used :: c:\documents and settings\a\Desktop\CFScript.txt

FILE ::
"c:\windows\system32\69a8c2.exe"
"c:\windows\system32\7a9cd3.exe"
"c:\windows\system32\7G-C2E36.EXE"
"c:\windows\system32\8X-E0925.EXE"
"c:\windows\system32\9W-7A730.EXE"
"c:\windows\system32\F62C71.EXE"
"c:\windows\system32\HV-D5E54.EXE"
"c:\windows\system32\HX-2579E.EXE"
"c:\windows\system32\vt-7326.exe"
"c:\windows\system32\vt-7626.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\69a8c2.exe
c:\windows\system32\7a9cd3.exe
c:\windows\system32\7G-C2E36.EXE
c:\windows\system32\8X-E0925.EXE
c:\windows\system32\9W-7A730.EXE
c:\windows\system32\F62C71.EXE
c:\windows\system32\HV-D5E54.EXE
c:\windows\system32\HX-2579E.EXE
c:\windows\system32\vt-7326.exe
c:\windows\system32\vt-7626.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ASC3360PR
-------\Service_asc3360pr


((((((((((((((((((((((((( Files Created from 2009-08-16 to 2009-09-16 )))))))))))))))))))))))))))))))
.

2009-09-16 15:28 . 2009-09-16 16:18 -------- d-----w- C:\ComboFix
2009-09-11 19:18 . 2009-09-11 19:19 -------- d-----w- C:\rsit
2009-09-05 14:03 . 2009-09-05 14:03 -------- d-----w- c:\documents and settings\a\Application Data\Malwarebytes
2009-09-05 14:03 . 2009-08-03 08:06 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-05 14:03 . 2009-09-05 14:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-05 14:03 . 2009-09-05 14:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-05 14:03 . 2009-08-03 08:06 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-28 11:20 . 2009-09-05 15:55 -------- d-----w- C:\SDFix
2009-08-27 16:56 . 2009-08-27 16:56 0 ----a-w- c:\windows\nsreg.dat
2009-08-27 16:56 . 2009-08-27 16:56 -------- d-----w- c:\documents and settings\a\Local Settings\Application Data\Mozilla
2009-08-27 12:28 . 2009-08-27 12:28 -------- d-----w- c:\documents and settings\a\Bluetooth Software
2009-08-23 11:32 . 2009-08-23 11:32 -------- d-----w- c:\program files\iPod
2009-08-23 11:32 . 2009-08-23 11:32 -------- d-----w- c:\program files\iTunes
2009-08-20 10:38 . 2001-08-17 08:32 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-08-20 10:38 . 2001-08-17 08:32 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-23 12:19 . 2009-07-02 03:15 -------- d-----w- c:\documents and settings\a\Application Data\U3
2009-08-23 11:32 . 2009-06-15 14:03 -------- d-----w- c:\program files\Common Files\Apple
.

------- Sigcheck -------

[-] 2009-06-16 . 8B9B057BCD245AF49C26463A3EEC93FB . 1032192 . . [6.00.2900.2180] . . c:\windows\explorer.exe
[-] 2009-06-16 . 8B9B057BCD245AF49C26463A3EEC93FB . 1032192 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-09-05_15.48.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 12:00 . 2009-09-05 15:38 40394 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-09-16 14:56 40394 c:\windows\system32\perfc009.dat
+ 2009-08-17 12:37 . 2005-03-31 09:02 503808 c:\windows\system32\VirtualExpander\VirtualExpander.exe
+ 2004-08-04 12:00 . 2009-09-16 14:56 312172 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2009-09-05 15:38 312172 c:\windows\system32\perfh009.dat
+ 2009-06-16 03:41 . 2008-02-28 16:00 215576 c:\windows\system32\igfxtray.exe
+ 2009-06-16 03:41 . 2008-02-28 16:00 215576 c:\windows\system32\igfxpers.exe
+ 2009-06-16 03:41 . 2008-02-28 16:00 240152 c:\windows\system32\hkcmd.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2009-08-17 12:37 73728 ----a-w- c:\windows\system32\VirtualExpander\VEShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-16 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-01-26 122880]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 215576]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 240152]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 215576]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-11-21 1471784]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 487424]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 113520]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 374048]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-12-26 18081280]

c:\documents and settings\a\Start Menu\Programs\Startup\
VirtualExpander.lnk - c:\windows\system32\VirtualExpander\VirtualExpander.exe [2009-8-17 503808]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-11-2 645736]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\SimpChinese\\setup.exe"=
"c:\\WINDOWS\\ALCMTR.EXE"=
"c:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe"=
"c:\\WINDOWS\\RTHDCPL.EXE"=
"c:\\Program Files\\Realtek\\Audio\\Drivers\\AzMixerSel.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\WINDOWS\\system32\\cleanmgr.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\iTunes\\iTunesHelper.exe"=
"c:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"=
"c:\\Program Files\\Adobe\\Reader 9.0\\Reader\\AcroRd32.exe"=
"c:\\Program Files\\QuickTime\\QTTask.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE"=
"c:\\WINDOWS\\system32\\cmd.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\at.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"d:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=
"c:\\WINDOWS\\system32\\CF27580.exe"=

R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [6/16/2009 9:16 AM 38400]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [6/16/2009 1:06 PM 66048]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [6/16/2009 9:14 AM 160256]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - ASC3360PR
.
Contents of the 'Scheduled Tasks' folder

2009-06-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\a\Application Data\Mozilla\Firefox\Profiles\pjujlvr0.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2009-09-16 21:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3048)
c:\windows\system32\VirtualExpander\VEShellExt.dll
c:\windows\system32\btmmhook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\docume~1\a\LOCALS~1\temp\RtkBtMnt.exe
.
**************************************************************************
.
Completion time: 2009-09-16 21:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-16 16:28
ComboFix2.txt 2009-09-14 17:05
ComboFix3.txt 2009-09-05 15:50

Pre-Run: 409,755,648 bytes free
Post-Run: 396,361,728 bytes free

185


Malwarebytes' Anti-Malware 1.41
Database version: 2812
Windows 5.1.2600 Service Pack 2

9/16/2009 10:36:03 PM
mbam-log-2009-09-16 (22-36-03).txt

Scan type: Quick Scan
Objects scanned: 84513
Time elapsed: 3 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\a\Local Settings\temp\lorer.exe (Worm.AutoRun) -> Delete on reboot.
Posted 9/16/2009 5:25 PM
#77435
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
I rebooted & ran Malawarebytes again - here's the log

Malwarebytes' Anti-Malware 1.41
Database version: 2812
Windows 5.1.2600 Service Pack 2

9/16/2009 10:54:52 PM
mbam-log-2009-09-16 (22-54-52).txt

Scan type: Quick Scan
Objects scanned: 84401
Time elapsed: 3 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\a\Local Settings\temp\romi.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\a\Local Settings\temp\winhswpsl.exe (Trojan.Downloader) -> Delete
Posted 9/16/2009 11:31 PM
#77439
User avatar

Jintan Advanced member

Date Joined Nov 2016
Total Posts: 1049
I received the file, thanks. Both copies of explorer.exe that ComboFix shows have been altered by a type of worm malware. That "autorun worm" Malwarebytes located is a part of the infection. Those are very likely the only two copies of explorer.exe there, so you will need to see if you can get a clean copy from some other computer, to replace these infected versions. The copy will need to come from the same Windows XP Professional Service Pack 2, from this location on that other computer:

c:\WINDOWS\explorer.exe <-----

Once you have that copy, place a copy of it directly in your C drive folder, so it will then be C:\explorer.exe, and post back here letting me know. Then we will move forward with repairs there.
Posted 9/18/2009 11:52 AM
#77478
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
Hi Jintan
there isn't really anyone I can get a copy of explorer.exe off - i'm travellling for the next few weeks. is there anywhere i can download it, even at cost? i really want to get this thing cleared up.
Posted 9/18/2009 4:45 PM
#77482
User avatar

Jintan Advanced member

Date Joined Nov 2016
Total Posts: 1049
No, not in any realistic or safe manner. Let's see if a scan can "heal" files instead there.


Download Dr.Web CureIt! from here to your Desktop.

When you have done this, boot into safe mode (restart your computer and tap F8 continuously as it restarts)

Doubleclick the drweb-cureit.exe file. Click on Start and Ok and allow it to run the express scan. This is a short scan and will scan all files currently running in memory. If something is found, click the Yes button when it asks you if you want to cure it.

Once the short scan has finished, click on Custom Scan and choose the drives that you want to scan. Click on the drive to select it. A red dot shows which drives have been chosen (if only one drive you will not be shown these options). Click the green arrow > to the right and the scan will begin. At the first sign of infection, Select 'Yes to all' if it asks if you want to cure/move the file.

When the scan has finished, click the "Select all" button and then click on the Move button. This will move any infected files to the %userprofile%\DoctorWeb\quarantine folder.

Next and this is important, from the main Dr.Web CureIt menu (top left), click File and choose save report list and save the report to your desktop. The report will be called DrWeb.csv and it can be opened in Notepad.

Close Cureit and restart your computer to completely remove any stubborn files. You may get a message saying "No operations performed with some objects in list. Exit program". If so, click "Yes" (You may get a popup offering you a discount if you purchase DrWeb AntiVirus. You may or may not wish to take advantage of this offer later but for now, just close the popup and wait for the scan to finish).

Please post the log in this thread.
Posted 9/18/2009 6:08 PM
#77485
User avatar

sarahviajera Valued member

Date Joined Nov 2016
Total Posts: 10
sorry - the last message was blank
Posted 9/18/2009 8:27 PM
#77486
User avatar

Jintan Advanced member

Date Joined Nov 2016
Total Posts: 1049
?? I am sorta blank on what you mean, actually. You cannot see the contents of the last post?
  • Unread posts or replies
  • No unread posts or replies
  • Unread Posts (Read Only Forum)
  • No Unread Posts (Read Only Forum)

Forum Information

Currently it is Monday, July 4, 2022, 7:57 AM (GMT +2)
There are a total of 61,974 posts in 13,697 threads.
In the last 3 days there were 0 new threads and 0 reply posts.

Who's online

This forum has 38,684 registered members. Please welcome our newest member, james44.
39 Guest(s), 0 Registered Member(s) are currently online.