Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > Malware and Virus Removal

Malware and Virus Removal Problems removing malware/viruses? Get help from our Malware removal experts.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 21st November 2008   #1
Member
 
Profile:
Join Date: Nov 2008
Posts: 6
Computer Experience:
intermediate
chayienne Reputation Level


[Resolved] Help Needed: How to Remove Infostealer.gampass trojan

Hi,

Yesterday, I inserted a USB flash drive which was infected with a trojan called infostealer.gampass. My Norton Internet Security flashed a message that the auto-protect feature has detected it. But instead of removing or preventing it from infecting my pc, the trojan has successfully crooned its way to my registry. Even worse, all the USB flash drives I have inserted have become infected.

I need help on how to remove this trojan from my pc. Is there also a way to disinfect the infected flash drives? Please advise.

Below is the hijackthis log :
--------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:00:33 AM, on 11/21/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ASTSRV.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\IDU\iptray.exe
C:\Program Files\Intel\IDU\awtray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Intel\IDU\IDUServ.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ipTray.exe] "C:\Program Files\Intel\IDU\iptray.exe"
O4 - HKLM\..\Run: [awTray.exe] "C:\Program Files\Intel\IDU\awtray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/tech...bs/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/tech...bs/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1211013477406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1211017270343
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{467F9AEB-6389-4F0D-AB34-31AD076ECE62}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Nalpeiron Licensing Service (ASTSRV) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Desktop Utilities Service (iHCService) - OSA Technologies, Inc. - C:\Program Files\Intel\IDU\IDUServ.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 11601 bytes

Thanks,
Chayienne

chayienne is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 23rd November 2008   #2
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,521
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Welcome to WindowsBBS chayienne

First, download Flash_Disinfector by sUBs and save it to your desktop.
  • Plug in your USB flash drive.
  • Double-click Flash_Disinfector.exe to run it.
  • Follow any prompts that may appear.
  • Your desktop will vanish for a while, and then reappear. This is normal.
  • Wait until the program has finished scanning, then please exit the program. If you use more than 1 flash drive, run the tool with each plugged in.

Next, we need to use another tool to scan that will show us a bit more.
  • Download RSIT by random/random and save it to your desktop.
  • Double click RSIT.exe to start the tool.
  • At the disclaimer, please use the drop down box to select 3 months for the file/folder search, then click Continue.
  • When the scan completes it will open a log named log.txt maximized, and a log named info.txt minimized.
  • Please post the contents of log.txt here in your next reply.

noahdfear is offline   Reply With Quote
Old 24th November 2008   #3
Member
 
Profile:
Join Date: Nov 2008
Posts: 6
Computer Experience:
intermediate
chayienne Reputation Level


Quote:
Originally Posted by noahdfear View Post
Welcome to WindowsBBS chayienne

First, download Flash_Disinfector by sUBs and save it to your desktop.
  • Plug in your USB flash drive.
  • Double-click Flash_Disinfector.exe to run it.
  • Follow any prompts that may appear.
  • Your desktop will vanish for a while, and then reappear. This is normal.
  • Wait until the program has finished scanning, then please exit the program. If you use more than 1 flash drive, run the tool with each plugged in.

Next, we need to use another tool to scan that will show us a bit more.
  • Download RSIT by random/random and save it to your desktop.
  • Double click RSIT.exe to start the tool.
  • At the disclaimer, please use the drop down box to select 3 months for the file/folder search, then click Continue.
  • When the scan completes it will open a log named log.txt maximized, and a log named info.txt minimized.
  • Please post the contents of log.txt here in your next reply.
Hi,

I have done as you instructed.

Here's the log:
Logfile of random's system information tool 1.04 (written by random/random)
Run by Hudson Ong at 2008-11-24 10:13:57
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 16 GB (21%) free of 76 GB
Total RAM: 1023 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:17 AM, on 11/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ASTSRV.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\IDU\iptray.exe
C:\Program Files\Intel\IDU\awtray.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Intel\IDU\IDUServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\Hudson Ong\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Hudson Ong.exe
C:\Program Files\Common Files\Symantec Shared\COH\coh32.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ipTray.exe] "C:\Program Files\Intel\IDU\iptray.exe"
O4 - HKLM\..\Run: [awTray.exe] "C:\Program Files\Intel\IDU\awtray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/tech...bs/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/tech...bs/tgctlsr.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1211013477406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1211017270343
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{467F9AEB-6389-4F0D-AB34-31AD076ECE62}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Nalpeiron Licensing Service (ASTSRV) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Desktop Utilities Service (iHCService) - OSA Technologies, Inc. - C:\Program Files\Intel\IDU\IDUServ.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 11743 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1211166262.job
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Hudson Ong.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll [2008-02-29 468280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-13 222448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll [2008-06-30 349552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2008-06-04 116088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-30 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-30 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-30 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-06-30 349552]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ipTray.exe"=C:\Program Files\Intel\IDU\iptray.exe [2005-04-29 1267200]
"awTray.exe"=C:\Program Files\Intel\IDU\awtray.exe [2005-03-11 1910784]
"farstone"= []
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"MSPY2002"=C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe [2003-03-31 59392]
"PHIME2002ASync"=C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
"PHIME2002A"=C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2008-10-17 51048]
"osCheck"=C:\Program Files\Norton Internet Security\osCheck.exe [2008-02-06 718704]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-01-11 577536]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2008-01-11 623992]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"Adobe_ID0EYTHM"=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EX E [2007-03-20 1884160]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-30 136600]
"Ulead AutoDetector v2"=C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [2005-05-23 90112]
"WinPatrol"=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2008-10-09 333120]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Upload Mgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Syste m]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableStatusMessages"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explor er]
"NoDriveTypeAutoRun"=36
"NoDriveAutoRun"=FFFFFFFF

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameter s\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@x psp2res.dll,-22019"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\kav\kis7.0\english\setup.exe"="C:\kav\kis7.0\english\setup.exe:*:Enable d:Kaspersky Internet Security 7.0 Setup"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Intuit\QuickBooks 2006\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2006\QBDBMgrN.exe:*:Enabled:QuickBooks 2006 Data Manager"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameter s\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@x psp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{412d05e6-2551-11dd-ade8-004095091a4d}]
shell\AutoRun\command - G:\bo1dhu.bat
shell\explore\command - G:\bo1dhu.bat
shell\open\command - G:\bo1dhu.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{7ce1c55a-b52b-11dd-aee9-004095091a4d}]
shell\AutoRun\command - G:\0w.com
shell\explore\command - G:\0w.com
shell\open\command - G:\0w.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{7ce1c55b-b52b-11dd-aee9-004095091a4d}]
shell\autoplAy\command - G:\ygbsy.pif
shell\AutoRun\command - G:\ygbsy.pif
shell\explorE\command - G:\ygbsy.pif
shell\OPen\command - G:\ygbsy.pif

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{c0e199fe-b6ab-11dd-aeec-004095091a4d}]
shell\AutoRun\command - G:\abk.bat
shell\explore\command - G:\abk.bat
shell\open\command - G:\abk.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{c8c2a070-49b2-11dd-ae34-004095091a4d}]
shell\AutoRun\command - G:\bo1dhu.bat
shell\explore\command - G:\bo1dhu.bat
shell\open\command - G:\bo1dhu.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{c8c2a071-49b2-11dd-ae34-004095091a4d}]
shell\AutoRun\command - G:\bo1dhu.bat
shell\explore\command - G:\bo1dhu.bat
shell\open\command - G:\bo1dhu.bat


======File associations======

.bat - edit - %SystemRoot%\System32\NOTEPAD.EXE %1"
.ini - open - %SystemRoot%\System32\NOTEPAD.EXE %1"

======List of files/folders created in the last 3 months======

2008-11-24 10:13:57 ----D---- C:\rsit
2008-11-21 11:00:34 ----D---- C:\Program Files\EsetOnlineScanner
2008-11-21 10:12:13 ----RASHD---- C:\autorun.inf
2008-11-19 11:52:55 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Malwarebytes
2008-11-19 11:52:40 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-19 11:52:40 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-11-19 10:55:21 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\WinPatrol
2008-11-19 10:55:06 ----D---- C:\Program Files\BillP Studios
2008-11-18 14:08:18 ----HD---- C:\WINDOWS\PIF
2008-11-17 09:55:21 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2008-11-13 18:37:39 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-11-13 18:37:22 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2008-11-05 10:45:24 ----HDC---- C:\WINDOWS\$NtUninstallKB954156_WM9L$
2008-11-04 11:09:59 ----N---- C:\WINDOWS\readme.txt
2008-11-04 10:32:41 ----D---- C:\Program Files\Novatix
2008-11-04 10:32:02 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-11-04 10:30:02 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Hemera
2008-11-04 10:15:57 ----D---- C:\WINDOWS\system32\windows media
2008-11-04 10:14:53 ----HD---- C:\WINDOWS\msdownld.tmp
2008-11-04 10:14:43 ----D---- C:\Program Files\Windows Media Components
2008-11-03 16:18:23 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\3D-Album-PS
2008-11-03 16:15:39 ----D---- C:\WINDOWS\system32\vscrsaver
2008-11-03 16:15:39 ----A---- C:\WINDOWS\system32\vaesaver.dll
2008-11-03 16:15:29 ----A---- C:\WINDOWS\system32\vaengine.dll
2008-11-03 16:15:28 ----D---- C:\Program Files\visviva
2008-11-03 16:14:47 ----D---- C:\Program Files\3D-Album-TR
2008-10-30 17:40:23 ----D---- C:\WINDOWS\Sun
2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\javaws.exe
2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\javaw.exe
2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\java.exe
2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-10-30 17:29:27 ----D---- C:\Program Files\Java
2008-10-30 17:13:32 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Sun
2008-10-25 14:43:04 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Alien Skin
2008-10-25 12:21:34 ----A---- C:\WINDOWS\system32\ASTSRV.EXE
2008-10-25 12:21:28 ----D---- C:\Program Files\Alien Skin
2008-10-24 19:01:04 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 11:34:12 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Help
2008-10-20 10:20:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-10-20 10:19:38 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-10-20 10:19:13 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-10-20 10:18:39 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-10-20 10:17:36 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-10-13 11:20:50 ----D---- C:\Program Files\Common Files\Control Panels
2008-10-13 11:12:14 ----D---- C:\Documents and Settings\All Users\Application Data\ALM
2008-10-13 10:37:47 ----D---- C:\Program Files\QuickTime
2008-10-13 10:34:35 ----A---- C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-10-13 10:34:35 ----A---- C:\WINDOWS\system32\NPSWF32.dll
2008-10-13 10:18:07 ----D---- C:\Program Files\Bonjour
2008-09-30 16:43:34 ----A---- C:\WINDOWS\system32\msxml4.dll
2008-09-30 10:18:35 ----A---- C:\WINDOWS\system32\cdintf250.dll
2008-09-30 10:11:38 ----D---- C:\Program Files\Intuit
2008-09-30 10:11:38 ----D---- C:\Program Files\Common Files\Intuit
2008-09-30 10:11:38 ----D---- C:\Documents and Settings\All Users\Application Data\Intuit
2008-09-30 10:07:41 ----D---- C:\Program Files\Common Files\SWF Studio
2008-09-29 17:34:38 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\BonkEnc
2008-09-29 17:17:09 ----D---- C:\Program Files\BonkEnc
2008-09-17 15:29:24 ----A---- C:\WINDOWS\Latin 8 Font Scrolling LED Display Uninstall Log.txt
2008-09-17 14:36:27 ----D---- C:\WINDOWS\Latin 8 Font Scrolling LED Display
2008-09-17 14:36:27 ----D---- C:\Program Files\Latin 8 Font Scrolling LED Display
2008-09-17 14:36:19 ----A---- C:\WINDOWS\Latin 8 Font Scrolling LED Display Setup Log.txt
2008-09-16 09:45:30 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2008-09-13 13:44:34 ----D---- C:\WINDOWS\Minidump
2008-09-12 18:49:20 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\LogoMaker
2008-09-12 13:48:24 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\COWON
2008-09-12 13:45:58 ----D---- C:\Program Files\Common Files\COWON
2008-09-12 13:45:57 ----D---- C:\Program Files\JetAudio
2008-09-12 13:43:58 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\InstallShield
2008-09-11 18:00:19 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\vxblock.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxwave.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxsfs.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxmas.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxdrv.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxafs.dll
2008-09-08 14:36:57 ----N---- C:\WINDOWS\system32\px.dll
2008-09-08 14:36:53 ----D---- C:\Program Files\Winamp
2008-09-08 14:36:53 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Winamp
2008-09-03 15:16:39 ----D---- C:\Program Files\Trend Micro
2008-09-02 12:48:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-09-01 10:35:29 ----D---- C:\WINDOWS\Prefetch
2008-09-01 10:25:52 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-09-01 10:25:39 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-09-01 10:25:23 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-09-01 10:25:08 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-09-01 10:24:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-09-01 10:24:37 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-09-01 10:23:53 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-09-01 10:23:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-09-01 10:23:19 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-09-01 10:23:03 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-09-01 10:14:55 ----D---- C:\WINDOWS\system32\scripting
2008-09-01 10:14:54 ----D---- C:\WINDOWS\l2schemas
2008-09-01 10:14:53 ----D---- C:\WINDOWS\system32\en
2008-08-26 13:52:32 ----N---- C:\WINDOWS\system32\wmphoto.dll
2008-08-26 13:52:22 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-08-26 13:52:08 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-26 13:52:05 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-26 13:51:30 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-08-26 13:51:30 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-08-26 13:51:11 ----N---- C:\WINDOWS\system32\setupn.exe
2008-08-26 13:51:06 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-26 13:51:04 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-08-26 13:51:03 ----N---- C:\WINDOWS\system32\qutil.dll
2008-08-26 13:51:00 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-08-26 13:51:00 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-08-26 13:51:00 ----N---- C:\WINDOWS\system32\qagent.dll
2008-08-26 13:50:58 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-26 13:50:53 ----N---- C:\WINDOWS\system32\onex.dll
2008-08-26 13:50:40 ----N---- C:\WINDOWS\system32\napstat.exe
2008-08-26 13:50:40 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-08-26 13:50:40 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-08-26 13:50:38 ----N---- C:\WINDOWS\system32\msxml6r.dll
2008-08-26 13:50:37 ----N---- C:\WINDOWS\system32\msxml6.dll
2008-08-26 13:50:35 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-26 13:50:35 ----N---- C:\WINDOWS\system32\mssha.dll
2008-08-26 13:50:16 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-08-26 13:50:16 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-26 13:50:16 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-08-26 13:50:16 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-26 13:50:04 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-26 13:50:03 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-08-26 13:50:02 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-08-26 13:50:02 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-26 13:50:02 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-26 13:50:02 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-26 13:49:47 ----A---- C:\WINDOWS\005366_.tmp
2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-08-26 13:49:40 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-08-26 13:49:40 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-26 13:49:39 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-26 13:49:37 ----N---- C:\WINDOWS\system32\credssp.dll
2008-08-26 13:49:31 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-26 13:49:31 ----N---- C:\WINDOWS\system32\azroles.dll
2008-08-26 13:49:21 ----N---- C:\WINDOWS\system32\aaclient.dll

======List of files/folders modified in the last 3 months======

2008-11-24 10:14:04 ----D---- C:\WINDOWS\Temp
2008-11-24 10:14:03 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-11-24 10:05:21 ----D---- C:\Program Files\Mozilla Firefox
2008-11-24 10:04:32 ----A---- C:\WINDOWS\win.ini
2008-11-24 10:04:26 ----SHD---- C:\WINDOWS\Installer
2008-11-24 10:03:20 ----D---- C:\WINDOWS\system32\CatRoot2
2008-11-22 19:03:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-11-22 15:01:12 ----D---- C:\WINDOWS\system32
2008-11-21 11:00:34 ----RD---- C:\Program Files
2008-11-21 10:55:35 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-11-20 19:00:39 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2008-11-20 15:59:27 ----D---- C:\WINDOWS\system32\drivers
2008-11-18 14:08:18 ----AD---- C:\WINDOWS
2008-11-18 14:00:09 ----HD---- C:\WINDOWS\inf
2008-11-17 09:55:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-11-17 09:53:35 ----D---- C:\WINDOWS\WinSxS
2008-11-13 18:37:45 ----A---- C:\WINDOWS\imsins.BAK
2008-11-13 18:37:35 ----HD---- C:\WINDOWS\$hf_mig$
2008-11-12 18:53:17 ----A---- C:\WINDOWS\NeroDigital.ini
2008-11-05 17:33:06 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Corel
2008-11-05 10:12:29 ----HD---- C:\Program Files\InstallShield Installation Information
2008-11-04 11:16:54 ----D---- C:\Program Files\Common Files\Ulead Systems
2008-11-04 11:09:37 ----D---- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-11-04 10:32:02 ----D---- C:\Program Files\Common Files
2008-11-04 10:15:57 ----D---- C:\WINDOWS\RegisteredPackages
2008-11-04 10:15:53 ----D---- C:\WINDOWS\system32\CatRoot
2008-11-04 10:13:39 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Ulead Systems
2008-11-04 10:11:47 ----D---- C:\Program Files\Ulead Systems
2008-11-04 08:10:25 ----A---- C:\WINDOWS\system32\MRT.exe
2008-11-03 13:45:40 ----A---- C:\WINDOWS\Iedit_.INI
2008-11-03 11:18:39 ----RSD---- C:\WINDOWS\Fonts
2008-10-25 14:32:53 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2008-10-25 14:31:56 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Adobe
2008-10-20 14:49:23 ----D---- C:\Program Files\Internet Explorer
2008-10-16 00:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll
2008-10-15 10:31:32 ----D---- C:\Program Files\Business-in-a-Box
2008-10-13 11:28:57 ----D---- C:\Program Files\Common Files\Adobe
2008-10-13 11:25:15 ----D---- C:\Program Files\Adobe
2008-10-04 01:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
2008-10-02 14:01:13 ----D---- C:\Documents and Settings
2008-09-30 11:38:36 ----SD---- C:\Documents and Settings\Hudson Ong\Application Data\Microsoft
2008-09-29 16:46:20 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-16 09:45:31 ----D---- C:\WINDOWS\Help
2008-09-13 14:23:42 ----SHD---- C:\System Volume Information
2008-09-13 14:23:42 ----D---- C:\WINDOWS\system32\Restore
2008-09-05 01:15:04 ----A---- C:\WINDOWS\system32\msxml3.dll
2008-09-01 10:38:11 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-01 10:36:42 ----A---- C:\WINDOWS\OEWABLog.txt
2008-09-01 10:35:39 ----A---- C:\WINDOWS\setuplog.txt
2008-09-01 10:34:39 ----D---- C:\WINDOWS\system32\wbem
2008-09-01 10:34:39 ----D---- C:\WINDOWS\system32\Setup
2008-09-01 10:34:39 ----D---- C:\WINDOWS\AppPatch
2008-09-01 10:33:59 ----D---- C:\WINDOWS\security
2008-09-01 10:23:05 ----D---- C:\Program Files\Messenger
2008-09-01 10:15:49 ----D---- C:\WINDOWS\ServicePackFiles
2008-09-01 10:15:48 ----D---- C:\Program Files\Windows Media Player
2008-09-01 10:15:24 ----D---- C:\WINDOWS\network diagnostic
2008-09-01 10:15:23 ----D---- C:\WINDOWS\ime
2008-09-01 10:14:59 ----D---- C:\WINDOWS\system32\usmt
2008-09-01 10:14:59 ----D---- C:\WINDOWS\system32\en-US
2008-09-01 10:14:52 ----D---- C:\WINDOWS\system32\bits
2008-09-01 10:14:52 ----D---- C:\WINDOWS\peernet
2008-09-01 10:14:52 ----D---- C:\Program Files\Movie Maker
2008-09-01 10:10:31 ----D---- C:\WINDOWS\system32\npp
2008-09-01 10:10:29 ----D---- C:\WINDOWS\msagent
2008-09-01 10:10:26 ----D---- C:\WINDOWS\srchasst
2008-09-01 10:10:15 ----D---- C:\Program Files\NetMeeting
2008-09-01 10:10:08 ----D---- C:\WINDOWS\system32\Com
2008-09-01 10:09:56 ----D---- C:\Program Files\Windows NT
2008-09-01 10:09:56 ----D---- C:\Program Files\Outlook Express
2008-09-01 10:09:52 ----D---- C:\Program Files\Common Files\System
2008-09-01 10:09:26 ----D---- C:\WINDOWS\system32\oobe
2008-09-01 10:09:14 ----D---- C:\WINDOWS\system
2008-09-01 10:02:25 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-09-01 10:01:59 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-09-01 09:57:43 ----D---- C:\WINDOWS\EHome
2008-08-27 18:58:23 ----D---- C:\totalcmd
2008-08-27 16:24:32 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-08-26 15:24:31 ----A---- C:\WINDOWS\system32\wininet.dll
2008-08-26 15:24:31 ----A---- C:\WINDOWS\system32\webcheck.dll
2008-08-26 15:24:31 ----A---- C:\WINDOWS\system32\urlmon.dll
2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\pngfilt.dll
2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\occache.dll
2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\mstime.dll
2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\msrating.dll
2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\mshtmled.dll
2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\jsproxy.dll
2008-08-26 15:24:30 ----A---- C:\WINDOWS\system32\url.dll
2008-08-26 15:24:30 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2008-08-26 15:24:30 ----A---- C:\WINDOWS\system32\msfeeds.dll
2008-08-26 15:24:29 ----N---- C:\WINDOWS\system32\iernonce.dll
2008-08-26 15:24:29 ----N---- C:\WINDOWS\system32\iedkcs32.dll
2008-08-26 15:24:29 ----A---- C:\WINDOWS\system32\iertutil.dll
2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\ieaksie.dll
2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\ieakeng.dll
2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\extmgr.dll
2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\dxtrans.dll
2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\dxtmsft.dll
2008-08-26 15:24:28 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2008-08-26 15:24:28 ----A---- C:\WINDOWS\system32\icardie.dll
2008-08-26 15:24:28 ----A---- C:\WINDOWS\system32\advpack.dll
2008-08-26 12:09:17 ----D---- C:\WINDOWS\Debug
2008-08-25 16:38:00 ----A---- C:\WINDOWS\system32\ieudinit.exe
2008-08-25 16:37:59 ----N---- C:\WINDOWS\system32\ie4uinit.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2004-10-08 35840]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
R1 SRTSP;SRTSP; C:\WINDOWS\System32\Drivers\SRTSP.SYS [2008-01-31 279088]
R1 SRTSPX;SRTSPX; C:\WINDOWS\System32\Drivers\SRTSPX.SYS [2008-01-31 43696]
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2008-06-13 184240]
R2 CO_Mon;CO_Mon; \??\C:\WINDOWS\system32\drivers\CO_Mon.sys []
R2 OsaFsLoc;OsaFsLoc; \??\C:\WINDOWS\System32\drivers\OsaFsLoc.sys []
R2 osaio;osaio; \??\C:\WINDOWS\System32\drivers\osaio.sys []
R2 SIODRV;SIODRV; \??\C:\WINDOWS\System32\drivers\SIODRV.SYS []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-02-08 3846016]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081121.050\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081121.050\NAVEX15.SYS []
R3 NTIDrvr;Upper Class Filter Driver; C:\WINDOWS\System32\DRIVERS\NTIDrvr.sys [2008-05-17 6144]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\System32\DRIVERS\SMBios.sys [2003-11-03 36484]
R3 smbusp;Intel(R) SMBus 2.0 Driver; C:\WINDOWS\System32\DRIVERS\intelsmb.sys [2005-03-15 21248]
R3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2008-06-13 13616]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2008-06-13 96432]
R3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2008-06-13 38576]
R3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\ipsdefs\20081120.001\SymIDSCo.sy s []
R3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
R3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2008-06-13 37424]
R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2008-06-13 22320]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 COH_Mon;COH_Mon; \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys []
S3 exdisk;Express Disk Service; C:\WINDOWS\System32\DRIVERS\exdisk.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [2003-04-11 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [2003-04-11 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [2003-04-11 21456]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
S3 SRTSPL;SRTSPL; C:\WINDOWS\System32\Drivers\SRTSPL.SYS [2008-01-31 317616]
S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASTSRV;Nalpeiron Licensing Service; C:\WINDOWS\system32\ASTSRV.EXE [2008-05-19 57344]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2008-02-09 238968]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 iHCService;Intel(R) Desktop Utilities Service; C:\Program Files\Intel\IDU\IDUServ.exe [2005-04-29 1302016]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-30 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
R2 LiveUpdate Notice;LiveUpdate Notice; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-06-12 654848]
R3 Symantec Core LC;Symantec Core LC; C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [2008-06-04 1245064]
S3 Adobe Version Cue CS3;Adobe Version Cue CS3; C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe [2007-03-20 153792]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 comHost;COM Host; C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [2007-08-22 55640]
S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2008-08-04 3220856]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.exe [2003-04-11 65795]

-----------------EOF-----------------

Thanks,
Chayienne

chayienne is offline   Reply With Quote
Old 24th November 2008   #4
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,521
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Highlight and copy the contents of the code box below.
Code:
reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{412d05e6-2551-11dd-ade8-004095091a4d} /f
reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ce1c55a-b52b-11dd-aee9-004095091a4d} /f
reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ce1c55b-b52b-11dd-aee9-004095091a4d} /f
reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0e199fe-b6ab-11dd-aeec-004095091a4d} /f
reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8c2a070-49b2-11dd-ae34-004095091a4d} /f
reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8c2a071-49b2-11dd-ae34-004095091a4d} /f
reg delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v farstone /f
reg delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v KernelFaultCheck /f
exit
cls
Click Start>Run and type cmd then hit enter to open a command window. Right click in the command window and select paste. The command window will close on it's own.


Now, download ATF Cleaner by Atribune and save it to your Desktop.
  • Double click ATF-Cleaner.exe to run the program.
  • Check the boxes to the left of:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Java Cache
    • Recycle bin

  • The rest are optional - if you want it to remove everything check "Select All".
  • Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK then exit.
Reboot


Finally, do an online scan with Kaspersky Online Scanner

Click Accept, when prompted to download and install the program files and database of malware definitions.
  • Click Run at the Security prompt.
  • The program will then begin downloading and installing and will also update the database.
  • Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click View scan report at the bottom.
  • Click the Save Report As... button.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.
**Note**

To optimize scanning time and produce a more sensible report for review:
  • Close any open programs.
  • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.
Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.


Post the Kaspersky log here.

noahdfear is offline   Reply With Quote
Old 25th November 2008   #5
Member
 
Profile:
Join Date: Nov 2008
Posts: 6
Computer Experience:
intermediate
chayienne Reputation Level


Hi,
I have two hard disks on my pc. Should I also scan the other hard disk?
Will post the online scan results tomorrow.

Regards,
Chayienne

chayienne is offline   Reply With Quote
Old 25th November 2008   #6
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,521
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Certainly won't hurt to scan both drives. Malware can and does sometimes find it's way to other partitions/drives.
noahdfear is offline   Reply With Quote
Old 27th November 2008   #7
Member
 
Profile:
Join Date: Nov 2008
Posts: 6
Computer Experience:
intermediate
chayienne Reputation Level


Hi,
I finished the scan today but there's no report when I clicked on the scan report button.
The scan was completed with no threats found in my pc. It took around 5 hours to scan my two hard drives. Should I re-scan and capture a screenshot of the results of the scan?


Regards,
Chayienne

chayienne is offline   Reply With Quote
Old 30th November 2008   #8
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,521
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

No need to repeat the Kaspersky scan. Please run RSIT again and post the new log.txt that opens when complete.
noahdfear is offline   Reply With Quote
Old 1st December 2008   #9
Member
 
Profile:
Join Date: Nov 2008
Posts: 6
Computer Experience:
intermediate
chayienne Reputation Level


Thanks for the reply. Here's the log:

Logfile of random's system information tool 1.04 (written by random/random)
Run by Hudson Ong at 2008-12-01 11:22:26
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 17 GB (22%) free of 76 GB
Total RAM: 1023 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:23:09 AM, on 12/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ASTSRV.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\IDU\iptray.exe
C:\Program Files\Intel\IDU\awtray.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Intel\IDU\IDUServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\Hudson Ong\My Documents\Cecile\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Hudson Ong.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ipTray.exe] "C:\Program Files\Intel\IDU\iptray.exe"
O4 - HKLM\..\Run: [awTray.exe] "C:\Program Files\Intel\IDU\awtray.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/tech...bs/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/tech...bs/tgctlsr.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1211013477406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1211017270343
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{467F9AEB-6389-4F0D-AB34-31AD076ECE62}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Nalpeiron Licensing Service (ASTSRV) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Desktop Utilities Service (iHCService) - OSA Technologies, Inc. - C:\Program Files\Intel\IDU\IDUServ.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 11532 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1211166262.job
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Hudson Ong.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll [2008-02-29 468280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-13 222448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll [2008-06-30 349552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2008-06-04 116088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-30 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-30 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-30 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-06-30 349552]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ipTray.exe"=C:\Program Files\Intel\IDU\iptray.exe [2005-04-29 1267200]
"awTray.exe"=C:\Program Files\Intel\IDU\awtray.exe [2005-03-11 1910784]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"MSPY2002"=C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe [2003-03-31 59392]
"PHIME2002ASync"=C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
"PHIME2002A"=C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2008-10-17 51048]
"osCheck"=C:\Program Files\Norton Internet Security\osCheck.exe [2008-02-06 718704]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-01-11 577536]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2008-01-11 623992]
"Adobe_ID0EYTHM"=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EX E [2007-03-20 1884160]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-30 136600]
"WinPatrol"=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2008-10-09 333120]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Upload Mgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Syste m]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableStatusMessages"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explor er]
"NoDriveTypeAutoRun"=36
"NoDriveAutoRun"=FFFFFFFF

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameter s\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@x psp2res.dll,-22019"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\kav\kis7.0\english\setup.exe"="C:\kav\kis7.0\english\setup.exe:*:Enable d:Kaspersky Internet Security 7.0 Setup"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Intuit\QuickBooks 2006\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2006\QBDBMgrN.exe:*:Enabled:QuickBooks 2006 Data Manager"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameter s\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@x psp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======File associations======

.bat - edit - %SystemRoot%\System32\NOTEPAD.EXE %1"
.ini - open - %SystemRoot%\System32\NOTEPAD.EXE %1"

======List of files/folders created in the last 3 months======

2008-11-24 10:13:57 ----D---- C:\rsit
2008-11-21 11:00:34 ----D---- C:\Program Files\EsetOnlineScanner
2008-11-21 10:12:13 ----RASHD---- C:\autorun.inf
2008-11-19 11:52:55 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Malwarebytes
2008-11-19 11:52:40 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-19 11:52:40 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-11-19 10:55:21 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\WinPatrol
2008-11-19 10:55:06 ----D---- C:\Program Files\BillP Studios
2008-11-18 14:08:18 ----HD---- C:\WINDOWS\PIF
2008-11-17 09:55:21 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2008-11-13 18:37:39 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-11-13 18:37:22 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2008-11-05 10:45:24 ----HDC---- C:\WINDOWS\$NtUninstallKB954156_WM9L$
2008-11-04 11:09:59 ----N---- C:\WINDOWS\readme.txt
2008-11-04 10:32:41 ----D---- C:\Program Files\Novatix
2008-11-04 10:32:02 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-11-04 10:30:02 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Hemera
2008-11-04 10:15:57 ----D---- C:\WINDOWS\system32\windows media
2008-11-04 10:14:53 ----HD---- C:\WINDOWS\msdownld.tmp
2008-11-04 10:14:43 ----D---- C:\Program Files\Windows Media Components
2008-11-03 16:18:23 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\3D-Album-PS
2008-11-03 16:15:39 ----D---- C:\WINDOWS\system32\vscrsaver
2008-11-03 16:15:39 ----A---- C:\WINDOWS\system32\vaesaver.dll
2008-11-03 16:15:29 ----A---- C:\WINDOWS\system32\vaengine.dll
2008-11-03 16:15:28 ----D---- C:\Program Files\visviva
2008-11-03 16:14:47 ----D---- C:\Program Files\3D-Album-TR
2008-10-30 17:40:23 ----D---- C:\WINDOWS\Sun
2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\javaws.exe
2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\javaw.exe
2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\java.exe
2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-10-30 17:29:27 ----D---- C:\Program Files\Java
2008-10-30 17:13:32 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Sun
2008-10-25 14:43:04 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Alien Skin
2008-10-25 12:21:34 ----A---- C:\WINDOWS\system32\ASTSRV.EXE
2008-10-25 12:21:28 ----D---- C:\Program Files\Alien Skin
2008-10-24 19:01:04 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-10-24 11:34:12 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Help
2008-10-20 10:20:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-10-20 10:19:38 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-10-20 10:19:13 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-10-20 10:18:39 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-10-20 10:17:36 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-10-13 11:20:50 ----D---- C:\Program Files\Common Files\Control Panels
2008-10-13 11:12:14 ----D---- C:\Documents and Settings\All Users\Application Data\ALM
2008-10-13 10:37:47 ----D---- C:\Program Files\QuickTime
2008-10-13 10:34:35 ----A---- C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-10-13 10:34:35 ----A---- C:\WINDOWS\system32\NPSWF32.dll
2008-10-13 10:18:07 ----D---- C:\Program Files\Bonjour
2008-09-30 16:43:34 ----A---- C:\WINDOWS\system32\msxml4.dll
2008-09-30 10:18:35 ----A---- C:\WINDOWS\system32\cdintf250.dll
2008-09-30 10:11:38 ----D---- C:\Program Files\Intuit
2008-09-30 10:11:38 ----D---- C:\Program Files\Common Files\Intuit
2008-09-30 10:11:38 ----D---- C:\Documents and Settings\All Users\Application Data\Intuit
2008-09-30 10:07:41 ----D---- C:\Program Files\Common Files\SWF Studio
2008-09-29 17:34:38 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\BonkEnc
2008-09-29 17:17:09 ----D---- C:\Program Files\BonkEnc
2008-09-17 15:29:24 ----A---- C:\WINDOWS\Latin 8 Font Scrolling LED Display Uninstall Log.txt
2008-09-17 14:36:27 ----D---- C:\WINDOWS\Latin 8 Font Scrolling LED Display
2008-09-17 14:36:27 ----D---- C:\Program Files\Latin 8 Font Scrolling LED Display
2008-09-17 14:36:19 ----A---- C:\WINDOWS\Latin 8 Font Scrolling LED Display Setup Log.txt
2008-09-16 09:45:30 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2008-09-13 13:44:34 ----D---- C:\WINDOWS\Minidump
2008-09-12 18:49:20 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\LogoMaker
2008-09-12 13:48:24 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\COWON
2008-09-12 13:45:58 ----D---- C:\Program Files\Common Files\COWON
2008-09-12 13:45:57 ----D---- C:\Program Files\JetAudio
2008-09-12 13:43:58 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\InstallShield
2008-09-11 18:00:19 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\vxblock.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxwave.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxsfs.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxmas.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxdrv.dll
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxafs.dll
2008-09-08 14:36:57 ----N---- C:\WINDOWS\system32\px.dll
2008-09-08 14:36:53 ----D---- C:\Program Files\Winamp
2008-09-08 14:36:53 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Winamp
2008-09-03 15:16:39 ----D---- C:\Program Files\Trend Micro
2008-09-02 12:48:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$

======List of files/folders modified in the last 3 months======

2008-12-01 11:22:45 ----D---- C:\WINDOWS\Temp
2008-12-01 11:22:44 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-12-01 11:22:31 ----D---- C:\WINDOWS\Prefetch
2008-12-01 11:05:06 ----D---- C:\Program Files\Mozilla Firefox
2008-12-01 10:36:23 ----A---- C:\WINDOWS\win.ini
2008-12-01 10:36:22 ----SHD---- C:\WINDOWS\Installer
2008-12-01 10:36:16 ----D---- C:\WINDOWS\system32
2008-12-01 10:24:50 ----AD---- C:\WINDOWS
2008-12-01 10:24:45 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-01 10:24:38 ----D---- C:\WINDOWS\system32\CatRoot2
2008-11-29 18:53:32 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-11-29 15:05:33 ----HD---- C:\WINDOWS\inf
2008-11-29 15:05:33 ----D---- C:\WINDOWS\Help
2008-11-28 18:37:39 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Corel
2008-11-27 11:45:49 ----A---- C:\WINDOWS\NeroDigital.ini
2008-11-21 11:00:34 ----RD---- C:\Program Files
2008-11-21 10:55:35 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-11-20 19:00:39 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2008-11-20 15:59:27 ----D---- C:\WINDOWS\system32\drivers
2008-11-17 09:53:35 ----D---- C:\WINDOWS\WinSxS
2008-11-13 18:37:45 ----A---- C:\WINDOWS\imsins.BAK
2008-11-13 18:37:35 ----HD---- C:\WINDOWS\$hf_mig$
2008-11-05 10:12:29 ----HD---- C:\Program Files\InstallShield Installation Information
2008-11-04 11:16:54 ----D---- C:\Program Files\Common Files\Ulead Systems
2008-11-04 11:09:37 ----D---- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-11-04 10:32:02 ----D---- C:\Program Files\Common Files
2008-11-04 10:15:57 ----D---- C:\WINDOWS\RegisteredPackages
2008-11-04 10:15:53 ----D---- C:\WINDOWS\system32\CatRoot
2008-11-04 10:13:39 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Ulead Systems
2008-11-04 10:11:47 ----D---- C:\Program Files\Ulead Systems
2008-11-04 08:10:25 ----A---- C:\WINDOWS\system32\MRT.exe
2008-11-03 13:45:40 ----A---- C:\WINDOWS\Iedit_.INI
2008-11-03 11:18:39 ----RSD---- C:\WINDOWS\Fonts
2008-10-25 14:32:53 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2008-10-25 14:31:56 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Adobe
2008-10-20 14:49:23 ----D---- C:\Program Files\Internet Explorer
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wups2.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
2008-10-16 14:09:40 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2008-10-16 14:08:58 ----A---- C:\WINDOWS\system32\wups.dll
2008-10-16 14:07:44 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2008-10-16 14:07:14 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2008-10-16 14:06:48 ----A---- C:\WINDOWS\system32\muweb.dll
2008-10-16 14:06:48 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2008-10-16 14:06:48 ----A---- C:\WINDOWS\system32\mucltui.dll
2008-10-16 00:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll
2008-10-15 10:31:32 ----D---- C:\Program Files\Business-in-a-Box
2008-10-13 11:28:57 ----D---- C:\Program Files\Common Files\Adobe
2008-10-13 11:25:15 ----D---- C:\Program Files\Adobe
2008-10-04 01:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
2008-10-02 14:01:13 ----D---- C:\Documents and Settings
2008-09-30 11:38:36 ----SD---- C:\Documents and Settings\Hudson Ong\Application Data\Microsoft
2008-09-29 16:46:20 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-13 14:23:42 ----SHD---- C:\System Volume Information
2008-09-13 14:23:42 ----D---- C:\WINDOWS\system32\Restore
2008-09-10 09:14:56 ----N---- C:\WINDOWS\system32\msxml6.dll
2008-09-05 01:15:04 ----A---- C:\WINDOWS\system32\msxml3.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2004-10-08 35840]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
R1 SRTSP;SRTSP; C:\WINDOWS\System32\Drivers\SRTSP.SYS [2008-01-31 279088]
R1 SRTSPX;SRTSPX; C:\WINDOWS\System32\Drivers\SRTSPX.SYS [2008-01-31 43696]
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2008-06-13 184240]
R2 CO_Mon;CO_Mon; \??\C:\WINDOWS\system32\drivers\CO_Mon.sys []
R2 OsaFsLoc;OsaFsLoc; \??\C:\WINDOWS\System32\drivers\OsaFsLoc.sys []
R2 osaio;osaio; \??\C:\WINDOWS\System32\drivers\osaio.sys []
R2 SIODRV;SIODRV; \??\C:\WINDOWS\System32\drivers\SIODRV.SYS []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-02-08 3846016]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [2003-04-11 51024]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [2003-04-11 16080]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [2003-04-11 21456]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081130.023\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081130.023\NAVEX15.SYS []
R3 NTIDrvr;Upper Class Filter Driver; C:\WINDOWS\System32\DRIVERS\NTIDrvr.sys [2008-05-17 6144]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\System32\DRIVERS\SMBios.sys [2003-11-03 36484]
R3 smbusp;Intel(R) SMBus 2.0 Driver; C:\WINDOWS\System32\DRIVERS\intelsmb.sys [2005-03-15 21248]
R3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2008-06-13 13616]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2008-06-13 96432]
R3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2008-06-13 38576]
R3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\ipsdefs\20081127.002\SymIDSCo.sy s []
R3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
R3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2008-06-13 37424]
R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2008-06-13 22320]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 COH_Mon;COH_Mon; \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys []
S3 exdisk;Express Disk Service; C:\WINDOWS\System32\DRIVERS\exdisk.sys []
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
S3 SRTSPL;SRTSPL; C:\WINDOWS\System32\Drivers\SRTSPL.SYS [2008-01-31 317616]
S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASTSRV;Nalpeiron Licensing Service; C:\WINDOWS\system32\ASTSRV.EXE [2008-05-19 57344]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2008-02-09 238968]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 iHCService;Intel(R) Desktop Utilities Service; C:\Program Files\Intel\IDU\IDUServ.exe [2005-04-29 1302016]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-30 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
R2 LiveUpdate Notice;LiveUpdate Notice; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-06-12 654848]
R3 Symantec Core LC;Symantec Core LC; C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [2008-06-04 1245064]
S3 Adobe Version Cue CS3;Adobe Version Cue CS3; C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe [2007-03-20 153792]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 comHost;COM Host; C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [2007-08-22 55640]
S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2008-08-04 3220856]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.exe [2003-04-11 65795]

-----------------EOF-----------------

Regards,
Chayienne

chayienne is offline   Reply With Quote
Old 2nd December 2008   #10
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,521
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Log looks fine.
A couple of entries that do nothing to remove though. Please scan with HijackThis and place a check next to the following entries, then click Fixed Checked.

O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')

You can exit HijackThis once it processes those.

You can now delete Flash_Disinfector.exe, RSIT.exe and the C:\rsit folder.
Open MBAM and remove any items in quarantine.
Run ATF Cleaner again to clear temps and empty the recycle bin.

If you're satisfied that the computer is working properly, I recommend you clear the System Restore points.

Clear past system restore points and create a new one.
Right click My Computer and select Properties. On the System Restore tab, check the box to turn System Restore off. Click Apply. Now, uncheck the box and click Apply to turn System Restore back on. Click OK, then OK to close the System Properties dialog.

Verify a new restore point was created.
Click Start>All Programs>Accessories>System Tools>System Restore
Select 'Restore my computer to an earlier time', then click next.
You should have a newly created System Checkpoint available. If so, click Cancel. If not, click Back and select 'Create a restore point' then click Next. Give the restore point a name and click next.


Let me know if any issues remain.

noahdfear is offline   Reply With Quote
Old 3rd December 2008   #11
Member
 
Profile:
Join Date: Nov 2008
Posts: 6
Computer Experience:
intermediate
chayienne Reputation Level


Thank you very much for all your help. My PC is working fine now.

Regards,
Chayienne

chayienne is offline   Reply With Quote
Old 3rd December 2008   #12
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,521
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Glad to hear it, and happy I could help. You're most welcome. Geri has posted some very helpful information and recommendations regarding future protection in the following link.

An ounce of prevention is worth a pound of cure

Surf safe!

noahdfear is offline   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Resolved] Trojan/Virus Adware Serious problem living life Malware and Virus Removal 35 3rd August 2008 05:45
[Resolved] Help infostealer.gampass keep popping up , can't remove. jalanmo Malware and Virus Removal 3 16th July 2008 05:06
Trojan - Win32.Agent.gvu - trying to remove it alkster Malware and Virus Removal 5 5th July 2008 05:57
[Resolved] Hijackthis won't remove some references MitchellCooley Malware and Virus Removal 7 3rd July 2008 04:06
Trojan Dropper and Trojan Dialler - help needed quirkymac Malware and Virus Removal 16 17th September 2006 11:45


All times are GMT +1. The time now is 01:14.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]