1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Help Needed: How to Remove Infostealer.gampass trojan

Discussion in 'Malware and Virus Removal Archive' started by chayienne, 2008/11/20.

  1. 2008/11/20
    chayienne

    chayienne Inactive Thread Starter

    Joined:
    2008/11/20
    Messages:
    6
    Likes Received:
    0
    [Resolved] Help Needed: How to Remove Infostealer.gampass trojan

    Hi,

    Yesterday, I inserted a USB flash drive which was infected with a trojan called infostealer.gampass. My Norton Internet Security flashed a message that the auto-protect feature has detected it. But instead of removing or preventing it from infecting my pc, the trojan has successfully crooned its way to my registry. Even worse, all the USB flash drives I have inserted have become infected.

    I need help on how to remove this trojan from my pc. Is there also a way to disinfect the infected flash drives? Please advise.

    Below is the hijackthis log :
    --------------------------
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:00:33 AM, on 11/21/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\ASTSRV.EXE
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\IDU\iptray.exe
    C:\Program Files\Intel\IDU\awtray.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\WINDOWS\System32\msiexec.exe
    C:\Program Files\Intel\IDU\IDUServ.exe
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [ipTray.exe] "C:\Program Files\Intel\IDU\iptray.exe "
    O4 - HKLM\..\Run: [awTray.exe] "C:\Program Files\Intel\IDU\awtray.exe "
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe "
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe "
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe "
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe "
    O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsi.cab
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211013477406
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1211017270343
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{467F9AEB-6389-4F0D-AB34-31AD076ECE62}: NameServer = 208.67.222.222,208.67.220.220
    O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
    O23 - Service: Nalpeiron Licensing Service (ASTSRV) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Intel(R) Desktop Utilities Service (iHCService) - OSA Technologies, Inc. - C:\Program Files\Intel\IDU\IDUServ.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

    --
    End of file - 11601 bytes

    Thanks,
    Chayienne
     
  2. 2008/11/22
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Welcome to WindowsBBS chayienne :)

    First, download Flash_Disinfector by sUBs and save it to your desktop.
    • Plug in your USB flash drive.
    • Double-click Flash_Disinfector.exe to run it.
    • Follow any prompts that may appear.
    • Your desktop will vanish for a while, and then reappear. This is normal.
    • Wait until the program has finished scanning, then please exit the program. If you use more than 1 flash drive, run the tool with each plugged in.

    Next, we need to use another tool to scan that will show us a bit more.

    • Download RSIT by random/random and save it to your desktop.
    • Double click RSIT.exe to start the tool.
    • At the disclaimer, please use the drop down box to select 3 months for the file/folder search, then click Continue.
    • When the scan completes it will open a log named log.txt maximized, and a log named info.txt minimized.
    • Please post the contents of log.txt here in your next reply.
     

  3. to hide this advert.

  4. 2008/11/23
    chayienne

    chayienne Inactive Thread Starter

    Joined:
    2008/11/20
    Messages:
    6
    Likes Received:
    0
    Hi,

    I have done as you instructed.

    Here's the log:
    Logfile of random's system information tool 1.04 (written by random/random)
    Run by Hudson Ong at 2008-11-24 10:13:57
    Microsoft Windows XP Home Edition Service Pack 3
    System drive C: has 16 GB (21%) free of 76 GB
    Total RAM: 1023 MB (51% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:14:17 AM, on 11/24/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\ASTSRV.EXE
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\IDU\iptray.exe
    C:\Program Files\Intel\IDU\awtray.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\WINDOWS\System32\msiexec.exe
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Program Files\Intel\IDU\IDUServ.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    C:\Documents and Settings\Hudson Ong\Desktop\RSIT.exe
    C:\Program Files\Trend Micro\HijackThis\Hudson Ong.exe
    C:\Program Files\Common Files\Symantec Shared\COH\coh32.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [ipTray.exe] "C:\Program Files\Intel\IDU\iptray.exe "
    O4 - HKLM\..\Run: [awTray.exe] "C:\Program Files\Intel\IDU\awtray.exe "
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe "
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe "
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe "
    O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsi.cab
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211013477406
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1211017270343
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{467F9AEB-6389-4F0D-AB34-31AD076ECE62}: NameServer = 208.67.222.222,208.67.220.220
    O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
    O23 - Service: Nalpeiron Licensing Service (ASTSRV) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Intel(R) Desktop Utilities Service (iHCService) - OSA Technologies, Inc. - C:\Program Files\Intel\IDU\IDUServ.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

    --
    End of file - 11743 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1211166262.job
    C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Hudson Ong.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
    BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll [2008-02-29 468280]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
    Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-13 222448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
    C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll [2008-06-30 349552]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
    Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2008-06-04 116088]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-30 320920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
    Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-30 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-30 73728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-06-30 349552]
    {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "ipTray.exe "=C:\Program Files\Intel\IDU\iptray.exe [2005-04-29 1267200]
    "awTray.exe "=C:\Program Files\Intel\IDU\awtray.exe [2005-03-11 1910784]
    "farstone "= []
    "IMJPMIG8.1 "=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
    "MSPY2002 "=C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe [2003-03-31 59392]
    "PHIME2002ASync "=C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
    "PHIME2002A "=C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
    "NeroFilterCheck "=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
    "Adobe Reader Speed Launcher "=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
    "ccApp "=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2008-10-17 51048]
    "osCheck "=C:\Program Files\Norton Internet Security\osCheck.exe [2008-02-06 718704]
    "SoundMan "=C:\WINDOWS\SOUNDMAN.EXE [2006-01-11 577536]
    "Acrobat Assistant 8.0 "=C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2008-01-11 623992]
    "KernelFaultCheck "=C:\WINDOWS\system32\dumprep 0 -k []
    "Adobe_ID0EYTHM "=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE [2007-03-20 1884160]
    "SunJavaUpdateSched "=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-30 136600]
    "Ulead AutoDetector v2 "=C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [2005-05-23 90112]
    "WinPatrol "=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2008-10-09 333120]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername "=0
    "legalnoticecaption "=
    "legalnoticetext "=
    "shutdownwithoutlogon "=1
    "undockwithoutlogon "=1
    "DisableStatusMessages "=0

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun "=36
    "NoDriveAutoRun "=FFFFFFFF

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe "= "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger "
    "C:\Program Files\Yahoo!\Messenger\YServer.exe "= "C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server "
    "C:\kav\kis7.0\english\setup.exe "= "C:\kav\kis7.0\english\setup.exe:*:Enabled:Kaspersky Internet Security 7.0 Setup "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "C:\Program Files\Intuit\QuickBooks 2006\QBDBMgrN.exe "= "C:\Program Files\Intuit\QuickBooks 2006\QBDBMgrN.exe:*:Enabled:QuickBooks 2006 Data Manager "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{412d05e6-2551-11dd-ade8-004095091a4d}]
    shell\AutoRun\command - G:\bo1dhu.bat
    shell\explore\command - G:\bo1dhu.bat
    shell\open\command - G:\bo1dhu.bat

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ce1c55a-b52b-11dd-aee9-004095091a4d}]
    shell\AutoRun\command - G:\0w.com
    shell\explore\command - G:\0w.com
    shell\open\command - G:\0w.com

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ce1c55b-b52b-11dd-aee9-004095091a4d}]
    shell\autoplAy\command - G:\ygbsy.pif
    shell\AutoRun\command - G:\ygbsy.pif
    shell\explorE\command - G:\ygbsy.pif
    shell\OPen\command - G:\ygbsy.pif

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0e199fe-b6ab-11dd-aeec-004095091a4d}]
    shell\AutoRun\command - G:\abk.bat
    shell\explore\command - G:\abk.bat
    shell\open\command - G:\abk.bat

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8c2a070-49b2-11dd-ae34-004095091a4d}]
    shell\AutoRun\command - G:\bo1dhu.bat
    shell\explore\command - G:\bo1dhu.bat
    shell\open\command - G:\bo1dhu.bat

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8c2a071-49b2-11dd-ae34-004095091a4d}]
    shell\AutoRun\command - G:\bo1dhu.bat
    shell\explore\command - G:\bo1dhu.bat
    shell\open\command - G:\bo1dhu.bat


    ======File associations======

    .bat - edit - %SystemRoot%\System32\NOTEPAD.EXE %1 "
    .ini - open - %SystemRoot%\System32\NOTEPAD.EXE %1 "

    ======List of files/folders created in the last 3 months======

    2008-11-24 10:13:57 ----D---- C:\rsit
    2008-11-21 11:00:34 ----D---- C:\Program Files\EsetOnlineScanner
    2008-11-21 10:12:13 ----RASHD---- C:\autorun.inf
    2008-11-19 11:52:55 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Malwarebytes
    2008-11-19 11:52:40 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2008-11-19 11:52:40 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-11-19 10:55:21 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\WinPatrol
    2008-11-19 10:55:06 ----D---- C:\Program Files\BillP Studios
    2008-11-18 14:08:18 ----HD---- C:\WINDOWS\PIF
    2008-11-17 09:55:21 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
    2008-11-13 18:37:39 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
    2008-11-13 18:37:22 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
    2008-11-05 10:45:24 ----HDC---- C:\WINDOWS\$NtUninstallKB954156_WM9L$
    2008-11-04 11:09:59 ----N---- C:\WINDOWS\readme.txt
    2008-11-04 10:32:41 ----D---- C:\Program Files\Novatix
    2008-11-04 10:32:02 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
    2008-11-04 10:30:02 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Hemera
    2008-11-04 10:15:57 ----D---- C:\WINDOWS\system32\windows media
    2008-11-04 10:14:53 ----HD---- C:\WINDOWS\msdownld.tmp
    2008-11-04 10:14:43 ----D---- C:\Program Files\Windows Media Components
    2008-11-03 16:18:23 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\3D-Album-PS
    2008-11-03 16:15:39 ----D---- C:\WINDOWS\system32\vscrsaver
    2008-11-03 16:15:39 ----A---- C:\WINDOWS\system32\vaesaver.dll
    2008-11-03 16:15:29 ----A---- C:\WINDOWS\system32\vaengine.dll
    2008-11-03 16:15:28 ----D---- C:\Program Files\visviva
    2008-11-03 16:14:47 ----D---- C:\Program Files\3D-Album-TR
    2008-10-30 17:40:23 ----D---- C:\WINDOWS\Sun
    2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\javaws.exe
    2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\javaw.exe
    2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\java.exe
    2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\deploytk.dll
    2008-10-30 17:29:27 ----D---- C:\Program Files\Java
    2008-10-30 17:13:32 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Sun
    2008-10-25 14:43:04 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Alien Skin
    2008-10-25 12:21:34 ----A---- C:\WINDOWS\system32\ASTSRV.EXE
    2008-10-25 12:21:28 ----D---- C:\Program Files\Alien Skin
    2008-10-24 19:01:04 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2008-10-24 11:34:12 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Help
    2008-10-20 10:20:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2008-10-20 10:19:38 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
    2008-10-20 10:19:13 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
    2008-10-20 10:18:39 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
    2008-10-20 10:17:36 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
    2008-10-13 11:20:50 ----D---- C:\Program Files\Common Files\Control Panels
    2008-10-13 11:12:14 ----D---- C:\Documents and Settings\All Users\Application Data\ALM
    2008-10-13 10:37:47 ----D---- C:\Program Files\QuickTime
    2008-10-13 10:34:35 ----A---- C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
    2008-10-13 10:34:35 ----A---- C:\WINDOWS\system32\NPSWF32.dll
    2008-10-13 10:18:07 ----D---- C:\Program Files\Bonjour
    2008-09-30 16:43:34 ----A---- C:\WINDOWS\system32\msxml4.dll
    2008-09-30 10:18:35 ----A---- C:\WINDOWS\system32\cdintf250.dll
    2008-09-30 10:11:38 ----D---- C:\Program Files\Intuit
    2008-09-30 10:11:38 ----D---- C:\Program Files\Common Files\Intuit
    2008-09-30 10:11:38 ----D---- C:\Documents and Settings\All Users\Application Data\Intuit
    2008-09-30 10:07:41 ----D---- C:\Program Files\Common Files\SWF Studio
    2008-09-29 17:34:38 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\BonkEnc
    2008-09-29 17:17:09 ----D---- C:\Program Files\BonkEnc
    2008-09-17 15:29:24 ----A---- C:\WINDOWS\Latin 8 Font Scrolling LED Display Uninstall Log.txt
    2008-09-17 14:36:27 ----D---- C:\WINDOWS\Latin 8 Font Scrolling LED Display
    2008-09-17 14:36:27 ----D---- C:\Program Files\Latin 8 Font Scrolling LED Display
    2008-09-17 14:36:19 ----A---- C:\WINDOWS\Latin 8 Font Scrolling LED Display Setup Log.txt
    2008-09-16 09:45:30 ----D---- C:\WINDOWS\system32\SoftwareDistribution
    2008-09-13 13:44:34 ----D---- C:\WINDOWS\Minidump
    2008-09-12 18:49:20 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\LogoMaker
    2008-09-12 13:48:24 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\COWON
    2008-09-12 13:45:58 ----D---- C:\Program Files\Common Files\COWON
    2008-09-12 13:45:57 ----D---- C:\Program Files\JetAudio
    2008-09-12 13:43:58 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\InstallShield
    2008-09-11 18:00:19 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\vxblock.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxwave.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxsfs.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxmas.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxinsa64.exe
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxhpinst.exe
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxdrv.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxcpya64.exe
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxafs.dll
    2008-09-08 14:36:57 ----N---- C:\WINDOWS\system32\px.dll
    2008-09-08 14:36:53 ----D---- C:\Program Files\Winamp
    2008-09-08 14:36:53 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Winamp
    2008-09-03 15:16:39 ----D---- C:\Program Files\Trend Micro
    2008-09-02 12:48:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
    2008-09-01 10:35:29 ----D---- C:\WINDOWS\Prefetch
    2008-09-01 10:25:52 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
    2008-09-01 10:25:39 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
    2008-09-01 10:25:23 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
    2008-09-01 10:25:08 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
    2008-09-01 10:24:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
    2008-09-01 10:24:37 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
    2008-09-01 10:23:53 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
    2008-09-01 10:23:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
    2008-09-01 10:23:19 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
    2008-09-01 10:23:03 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
    2008-09-01 10:14:55 ----D---- C:\WINDOWS\system32\scripting
    2008-09-01 10:14:54 ----D---- C:\WINDOWS\l2schemas
    2008-09-01 10:14:53 ----D---- C:\WINDOWS\system32\en
    2008-08-26 13:52:32 ----N---- C:\WINDOWS\system32\wmphoto.dll
    2008-08-26 13:52:22 ----N---- C:\WINDOWS\system32\wlanapi.dll
    2008-08-26 13:52:08 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
    2008-08-26 13:52:05 ----N---- C:\WINDOWS\system32\windowscodecs.dll
    2008-08-26 13:51:30 ----N---- C:\WINDOWS\system32\tspkg.dll
    2008-08-26 13:51:30 ----N---- C:\WINDOWS\system32\tsgqec.dll
    2008-08-26 13:51:11 ----N---- C:\WINDOWS\system32\setupn.exe
    2008-08-26 13:51:06 ----N---- C:\WINDOWS\system32\rhttpaa.dll
    2008-08-26 13:51:04 ----N---- C:\WINDOWS\system32\rasqec.dll
    2008-08-26 13:51:03 ----N---- C:\WINDOWS\system32\qutil.dll
    2008-08-26 13:51:00 ----N---- C:\WINDOWS\system32\qcliprov.dll
    2008-08-26 13:51:00 ----N---- C:\WINDOWS\system32\qagentrt.dll
    2008-08-26 13:51:00 ----N---- C:\WINDOWS\system32\qagent.dll
    2008-08-26 13:50:58 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
    2008-08-26 13:50:53 ----N---- C:\WINDOWS\system32\onex.dll
    2008-08-26 13:50:40 ----N---- C:\WINDOWS\system32\napstat.exe
    2008-08-26 13:50:40 ----N---- C:\WINDOWS\system32\napmontr.dll
    2008-08-26 13:50:40 ----N---- C:\WINDOWS\system32\napipsec.dll
    2008-08-26 13:50:38 ----N---- C:\WINDOWS\system32\msxml6r.dll
    2008-08-26 13:50:37 ----N---- C:\WINDOWS\system32\msxml6.dll
    2008-08-26 13:50:35 ----N---- C:\WINDOWS\system32\msshavmsg.dll
    2008-08-26 13:50:35 ----N---- C:\WINDOWS\system32\mssha.dll
    2008-08-26 13:50:16 ----N---- C:\WINDOWS\system32\mmcperf.exe
    2008-08-26 13:50:16 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
    2008-08-26 13:50:16 ----N---- C:\WINDOWS\system32\mmcex.dll
    2008-08-26 13:50:16 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
    2008-08-26 13:50:04 ----N---- C:\WINDOWS\system32\l2gpstore.dll
    2008-08-26 13:50:03 ----N---- C:\WINDOWS\system32\kmsvc.dll
    2008-08-26 13:50:02 ----N---- C:\WINDOWS\system32\kbdpash.dll
    2008-08-26 13:50:02 ----N---- C:\WINDOWS\system32\kbdnepr.dll
    2008-08-26 13:50:02 ----N---- C:\WINDOWS\system32\kbdiultn.dll
    2008-08-26 13:50:02 ----N---- C:\WINDOWS\system32\kbdbhc.dll
    2008-08-26 13:49:47 ----A---- C:\WINDOWS\005366_.tmp
    2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapsvc.dll
    2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapqec.dll
    2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eappprxy.dll
    2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapphost.dll
    2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eappgnui.dll
    2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eappcfg.dll
    2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapp3hst.dll
    2008-08-26 13:49:44 ----N---- C:\WINDOWS\system32\eapolqec.dll
    2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3ui.dll
    2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3svc.dll
    2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3msm.dll
    2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
    2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3dlg.dll
    2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3cfg.dll
    2008-08-26 13:49:42 ----N---- C:\WINDOWS\system32\dot3api.dll
    2008-08-26 13:49:40 ----N---- C:\WINDOWS\system32\dimsroam.dll
    2008-08-26 13:49:40 ----N---- C:\WINDOWS\system32\dimsntfy.dll
    2008-08-26 13:49:39 ----N---- C:\WINDOWS\system32\dhcpqec.dll
    2008-08-26 13:49:37 ----N---- C:\WINDOWS\system32\credssp.dll
    2008-08-26 13:49:31 ----N---- C:\WINDOWS\system32\bitsprx4.dll
    2008-08-26 13:49:31 ----N---- C:\WINDOWS\system32\azroles.dll
    2008-08-26 13:49:21 ----N---- C:\WINDOWS\system32\aaclient.dll

    ======List of files/folders modified in the last 3 months======

    2008-11-24 10:14:04 ----D---- C:\WINDOWS\Temp
    2008-11-24 10:14:03 ----D---- C:\Program Files\Common Files\Symantec Shared
    2008-11-24 10:05:21 ----D---- C:\Program Files\Mozilla Firefox
    2008-11-24 10:04:32 ----A---- C:\WINDOWS\win.ini
    2008-11-24 10:04:26 ----SHD---- C:\WINDOWS\Installer
    2008-11-24 10:03:20 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-11-22 19:03:21 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-11-22 15:01:12 ----D---- C:\WINDOWS\system32
    2008-11-21 11:00:34 ----RD---- C:\Program Files
    2008-11-21 10:55:35 ----SD---- C:\WINDOWS\Downloaded Program Files
    2008-11-20 19:00:39 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
    2008-11-20 15:59:27 ----D---- C:\WINDOWS\system32\drivers
    2008-11-18 14:08:18 ----AD---- C:\WINDOWS
    2008-11-18 14:00:09 ----HD---- C:\WINDOWS\inf
    2008-11-17 09:55:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2008-11-17 09:53:35 ----D---- C:\WINDOWS\WinSxS
    2008-11-13 18:37:45 ----A---- C:\WINDOWS\imsins.BAK
    2008-11-13 18:37:35 ----HD---- C:\WINDOWS\$hf_mig$
    2008-11-12 18:53:17 ----A---- C:\WINDOWS\NeroDigital.ini
    2008-11-05 17:33:06 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Corel
    2008-11-05 10:12:29 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-11-04 11:16:54 ----D---- C:\Program Files\Common Files\Ulead Systems
    2008-11-04 11:09:37 ----D---- C:\Documents and Settings\All Users\Application Data\Ulead Systems
    2008-11-04 10:32:02 ----D---- C:\Program Files\Common Files
    2008-11-04 10:15:57 ----D---- C:\WINDOWS\RegisteredPackages
    2008-11-04 10:15:53 ----D---- C:\WINDOWS\system32\CatRoot
    2008-11-04 10:13:39 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Ulead Systems
    2008-11-04 10:11:47 ----D---- C:\Program Files\Ulead Systems
    2008-11-04 08:10:25 ----A---- C:\WINDOWS\system32\MRT.exe
    2008-11-03 13:45:40 ----A---- C:\WINDOWS\Iedit_.INI
    2008-11-03 11:18:39 ----RSD---- C:\WINDOWS\Fonts
    2008-10-25 14:32:53 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
    2008-10-25 14:31:56 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Adobe
    2008-10-20 14:49:23 ----D---- C:\Program Files\Internet Explorer
    2008-10-16 00:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll
    2008-10-15 10:31:32 ----D---- C:\Program Files\Business-in-a-Box
    2008-10-13 11:28:57 ----D---- C:\Program Files\Common Files\Adobe
    2008-10-13 11:25:15 ----D---- C:\Program Files\Adobe
    2008-10-04 01:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
    2008-10-02 14:01:13 ----D---- C:\Documents and Settings
    2008-09-30 11:38:36 ----SD---- C:\Documents and Settings\Hudson Ong\Application Data\Microsoft
    2008-09-29 16:46:20 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
    2008-09-16 09:45:31 ----D---- C:\WINDOWS\Help
    2008-09-13 14:23:42 ----SHD---- C:\System Volume Information
    2008-09-13 14:23:42 ----D---- C:\WINDOWS\system32\Restore
    2008-09-05 01:15:04 ----A---- C:\WINDOWS\system32\msxml3.dll
    2008-09-01 10:38:11 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2008-09-01 10:36:42 ----A---- C:\WINDOWS\OEWABLog.txt
    2008-09-01 10:35:39 ----A---- C:\WINDOWS\setuplog.txt
    2008-09-01 10:34:39 ----D---- C:\WINDOWS\system32\wbem
    2008-09-01 10:34:39 ----D---- C:\WINDOWS\system32\Setup
    2008-09-01 10:34:39 ----D---- C:\WINDOWS\AppPatch
    2008-09-01 10:33:59 ----D---- C:\WINDOWS\security
    2008-09-01 10:23:05 ----D---- C:\Program Files\Messenger
    2008-09-01 10:15:49 ----D---- C:\WINDOWS\ServicePackFiles
    2008-09-01 10:15:48 ----D---- C:\Program Files\Windows Media Player
    2008-09-01 10:15:24 ----D---- C:\WINDOWS\network diagnostic
    2008-09-01 10:15:23 ----D---- C:\WINDOWS\ime
    2008-09-01 10:14:59 ----D---- C:\WINDOWS\system32\usmt
    2008-09-01 10:14:59 ----D---- C:\WINDOWS\system32\en-US
    2008-09-01 10:14:52 ----D---- C:\WINDOWS\system32\bits
    2008-09-01 10:14:52 ----D---- C:\WINDOWS\peernet
    2008-09-01 10:14:52 ----D---- C:\Program Files\Movie Maker
    2008-09-01 10:10:31 ----D---- C:\WINDOWS\system32\npp
    2008-09-01 10:10:29 ----D---- C:\WINDOWS\msagent
    2008-09-01 10:10:26 ----D---- C:\WINDOWS\srchasst
    2008-09-01 10:10:15 ----D---- C:\Program Files\NetMeeting
    2008-09-01 10:10:08 ----D---- C:\WINDOWS\system32\Com
    2008-09-01 10:09:56 ----D---- C:\Program Files\Windows NT
    2008-09-01 10:09:56 ----D---- C:\Program Files\Outlook Express
    2008-09-01 10:09:52 ----D---- C:\Program Files\Common Files\System
    2008-09-01 10:09:26 ----D---- C:\WINDOWS\system32\oobe
    2008-09-01 10:09:14 ----D---- C:\WINDOWS\system
    2008-09-01 10:02:25 ----D---- C:\WINDOWS\system32\ReinstallBackups
    2008-09-01 10:01:59 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
    2008-09-01 09:57:43 ----D---- C:\WINDOWS\EHome
    2008-08-27 18:58:23 ----D---- C:\totalcmd
    2008-08-27 16:24:32 ----A---- C:\WINDOWS\system32\mshtml.dll
    2008-08-26 15:24:31 ----A---- C:\WINDOWS\system32\wininet.dll
    2008-08-26 15:24:31 ----A---- C:\WINDOWS\system32\webcheck.dll
    2008-08-26 15:24:31 ----A---- C:\WINDOWS\system32\urlmon.dll
    2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\pngfilt.dll
    2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\occache.dll
    2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\mstime.dll
    2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\msrating.dll
    2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\mshtmled.dll
    2008-08-26 15:24:30 ----N---- C:\WINDOWS\system32\jsproxy.dll
    2008-08-26 15:24:30 ----A---- C:\WINDOWS\system32\url.dll
    2008-08-26 15:24:30 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
    2008-08-26 15:24:30 ----A---- C:\WINDOWS\system32\msfeeds.dll
    2008-08-26 15:24:29 ----N---- C:\WINDOWS\system32\iernonce.dll
    2008-08-26 15:24:29 ----N---- C:\WINDOWS\system32\iedkcs32.dll
    2008-08-26 15:24:29 ----A---- C:\WINDOWS\system32\iertutil.dll
    2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\ieaksie.dll
    2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\ieakeng.dll
    2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\extmgr.dll
    2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\dxtrans.dll
    2008-08-26 15:24:28 ----N---- C:\WINDOWS\system32\dxtmsft.dll
    2008-08-26 15:24:28 ----A---- C:\WINDOWS\system32\ieapfltr.dll
    2008-08-26 15:24:28 ----A---- C:\WINDOWS\system32\icardie.dll
    2008-08-26 15:24:28 ----A---- C:\WINDOWS\system32\advpack.dll
    2008-08-26 12:09:17 ----D---- C:\WINDOWS\Debug
    2008-08-25 16:38:00 ----A---- C:\WINDOWS\system32\ieudinit.exe
    2008-08-25 16:37:59 ----N---- C:\WINDOWS\system32\ie4uinit.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2004-10-08 35840]
    R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
    R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
    R1 SRTSP;SRTSP; C:\WINDOWS\System32\Drivers\SRTSP.SYS [2008-01-31 279088]
    R1 SRTSPX;SRTSPX; C:\WINDOWS\System32\Drivers\SRTSPX.SYS [2008-01-31 43696]
    R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2008-06-13 184240]
    R2 CO_Mon;CO_Mon; \??\C:\WINDOWS\system32\drivers\CO_Mon.sys []
    R2 OsaFsLoc;OsaFsLoc; \??\C:\WINDOWS\System32\drivers\OsaFsLoc.sys []
    R2 osaio;osaio; \??\C:\WINDOWS\System32\drivers\osaio.sys []
    R2 SIODRV;SIODRV; \??\C:\WINDOWS\System32\drivers\SIODRV.SYS []
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-02-08 3846016]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
    R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081121.050\NAVENG.SYS []
    R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081121.050\NAVEX15.SYS []
    R3 NTIDrvr;Upper Class Filter Driver; C:\WINDOWS\System32\DRIVERS\NTIDrvr.sys [2008-05-17 6144]
    R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
    R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
    R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\System32\DRIVERS\SMBios.sys [2003-11-03 36484]
    R3 smbusp;Intel(R) SMBus 2.0 Driver; C:\WINDOWS\System32\DRIVERS\intelsmb.sys [2005-03-15 21248]
    R3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2008-06-13 13616]
    R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
    R3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2008-06-13 96432]
    R3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2008-06-13 38576]
    R3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\ipsdefs\20081120.001\SymIDSCo.sys []
    R3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
    R3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2008-06-13 37424]
    R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2008-06-13 22320]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
    S3 COH_Mon;COH_Mon; \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys []
    S3 exdisk;Express Disk Service; C:\WINDOWS\System32\DRIVERS\exdisk.sys []
    S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [2003-04-11 51024]
    S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [2003-04-11 16080]
    S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [2003-04-11 21456]
    S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
    S3 SRTSPL;SRTSPL; C:\WINDOWS\System32\Drivers\SRTSPL.SYS [2008-01-31 317616]
    S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
    S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
    S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
    S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-14 25856]
    S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-14 15104]
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 ASTSRV;Nalpeiron Licensing Service; C:\WINDOWS\system32\ASTSRV.EXE [2008-05-19 57344]
    R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2008-02-09 238968]
    R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
    R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
    R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
    R2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
    R2 iHCService;Intel(R) Desktop Utilities Service; C:\Program Files\Intel\IDU\IDUServ.exe [2005-04-29 1302016]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-30 152984]
    R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
    R2 LiveUpdate Notice;LiveUpdate Notice; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
    R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-06-12 654848]
    R3 Symantec Core LC;Symantec Core LC; C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [2008-06-04 1245064]
    S3 Adobe Version Cue CS3;Adobe Version Cue CS3; C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe [2007-03-20 153792]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
    S3 comHost;COM Host; C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [2007-08-22 55640]
    S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2008-08-04 3220856]
    S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.exe [2003-04-11 65795]

    -----------------EOF-----------------

    Thanks,
    Chayienne
     
  5. 2008/11/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Highlight and copy the contents of the code box below.
    Code:
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{412d05e6-2551-11dd-ade8-004095091a4d} /f
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ce1c55a-b52b-11dd-aee9-004095091a4d} /f
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ce1c55b-b52b-11dd-aee9-004095091a4d} /f
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0e199fe-b6ab-11dd-aeec-004095091a4d} /f
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8c2a070-49b2-11dd-ae34-004095091a4d} /f
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8c2a071-49b2-11dd-ae34-004095091a4d} /f
    reg delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v farstone /f
    reg delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v KernelFaultCheck /f
    exit
    cls
    
    Click Start>Run and type cmd then hit enter to open a command window. Right click in the command window and select paste. The command window will close on it's own.


    Now, download ATF Cleaner by Atribune and save it to your Desktop.
    • Double click ATF-Cleaner.exe to run the program.
    • Check the boxes to the left of:

      • Windows Temp
      • Current User Temp
      • All Users Temp
      • Temporary Internet Files
      • Prefetch
      • Java Cache
      • Recycle bin

    • The rest are optional - if you want it to remove everything check "Select All ".
    • Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK then exit.
    Reboot


    Finally, do an online scan with Kaspersky Online Scanner

    Click Accept, when prompted to download and install the program files and database of malware definitions.
    • Click Run at the Security prompt.
    • The program will then begin downloading and installing and will also update the database.
    • Please be patient as this can take several minutes.
    • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Click View scan report at the bottom.
    • Click the Save Report As... button.
    • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.
    **Note**

    To optimize scanning time and produce a more sensible report for review:
    • Close any open programs.
    • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.
    Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.


    Post the Kaspersky log here.
     
  6. 2008/11/25
    chayienne

    chayienne Inactive Thread Starter

    Joined:
    2008/11/20
    Messages:
    6
    Likes Received:
    0
    Hi,
    I have two hard disks on my pc. Should I also scan the other hard disk?
    Will post the online scan results tomorrow.

    Regards,
    Chayienne
     
  7. 2008/11/25
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Certainly won't hurt to scan both drives. Malware can and does sometimes find it's way to other partitions/drives.
     
  8. 2008/11/27
    chayienne

    chayienne Inactive Thread Starter

    Joined:
    2008/11/20
    Messages:
    6
    Likes Received:
    0
    Hi,
    I finished the scan today but there's no report when I clicked on the scan report button.
    The scan was completed with no threats found in my pc. It took around 5 hours to scan my two hard drives. Should I re-scan and capture a screenshot of the results of the scan?


    Regards,
    Chayienne
     
  9. 2008/11/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    No need to repeat the Kaspersky scan. Please run RSIT again and post the new log.txt that opens when complete.
     
  10. 2008/11/30
    chayienne

    chayienne Inactive Thread Starter

    Joined:
    2008/11/20
    Messages:
    6
    Likes Received:
    0
    Thanks for the reply. Here's the log:

    Logfile of random's system information tool 1.04 (written by random/random)
    Run by Hudson Ong at 2008-12-01 11:22:26
    Microsoft Windows XP Home Edition Service Pack 3
    System drive C: has 17 GB (22%) free of 76 GB
    Total RAM: 1023 MB (38% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:23:09 AM, on 12/1/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\ASTSRV.EXE
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\IDU\iptray.exe
    C:\Program Files\Intel\IDU\awtray.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    C:\Program Files\Intel\IDU\IDUServ.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\Documents and Settings\Hudson Ong\My Documents\Cecile\RSIT.exe
    C:\Program Files\Trend Micro\HijackThis\Hudson Ong.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [ipTray.exe] "C:\Program Files\Intel\IDU\iptray.exe "
    O4 - HKLM\..\Run: [awTray.exe] "C:\Program Files\Intel\IDU\awtray.exe "
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe "
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe "
    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe "
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsi.cab
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211013477406
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1211017270343
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{467F9AEB-6389-4F0D-AB34-31AD076ECE62}: NameServer = 208.67.222.222,208.67.220.220
    O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
    O23 - Service: Nalpeiron Licensing Service (ASTSRV) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Intel(R) Desktop Utilities Service (iHCService) - OSA Technologies, Inc. - C:\Program Files\Intel\IDU\IDUServ.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

    --
    End of file - 11532 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1211166262.job
    C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Hudson Ong.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
    BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll [2008-02-29 468280]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
    Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-13 222448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
    C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll [2008-06-30 349552]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
    Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2008-06-04 116088]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-30 320920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
    Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-30 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-30 73728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-06-30 349552]
    {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "ipTray.exe "=C:\Program Files\Intel\IDU\iptray.exe [2005-04-29 1267200]
    "awTray.exe "=C:\Program Files\Intel\IDU\awtray.exe [2005-03-11 1910784]
    "IMJPMIG8.1 "=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
    "MSPY2002 "=C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe [2003-03-31 59392]
    "PHIME2002ASync "=C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
    "PHIME2002A "=C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
    "NeroFilterCheck "=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
    "Adobe Reader Speed Launcher "=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
    "ccApp "=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2008-10-17 51048]
    "osCheck "=C:\Program Files\Norton Internet Security\osCheck.exe [2008-02-06 718704]
    "SoundMan "=C:\WINDOWS\SOUNDMAN.EXE [2006-01-11 577536]
    "Acrobat Assistant 8.0 "=C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2008-01-11 623992]
    "Adobe_ID0EYTHM "=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE [2007-03-20 1884160]
    "SunJavaUpdateSched "=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-30 136600]
    "WinPatrol "=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2008-10-09 333120]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername "=0
    "legalnoticecaption "=
    "legalnoticetext "=
    "shutdownwithoutlogon "=1
    "undockwithoutlogon "=1
    "DisableStatusMessages "=0

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun "=36
    "NoDriveAutoRun "=FFFFFFFF

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe "= "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger "
    "C:\Program Files\Yahoo!\Messenger\YServer.exe "= "C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server "
    "C:\kav\kis7.0\english\setup.exe "= "C:\kav\kis7.0\english\setup.exe:*:Enabled:Kaspersky Internet Security 7.0 Setup "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "C:\Program Files\Intuit\QuickBooks 2006\QBDBMgrN.exe "= "C:\Program Files\Intuit\QuickBooks 2006\QBDBMgrN.exe:*:Enabled:QuickBooks 2006 Data Manager "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "

    ======File associations======

    .bat - edit - %SystemRoot%\System32\NOTEPAD.EXE %1 "
    .ini - open - %SystemRoot%\System32\NOTEPAD.EXE %1 "

    ======List of files/folders created in the last 3 months======

    2008-11-24 10:13:57 ----D---- C:\rsit
    2008-11-21 11:00:34 ----D---- C:\Program Files\EsetOnlineScanner
    2008-11-21 10:12:13 ----RASHD---- C:\autorun.inf
    2008-11-19 11:52:55 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Malwarebytes
    2008-11-19 11:52:40 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2008-11-19 11:52:40 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-11-19 10:55:21 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\WinPatrol
    2008-11-19 10:55:06 ----D---- C:\Program Files\BillP Studios
    2008-11-18 14:08:18 ----HD---- C:\WINDOWS\PIF
    2008-11-17 09:55:21 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
    2008-11-13 18:37:39 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
    2008-11-13 18:37:22 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
    2008-11-05 10:45:24 ----HDC---- C:\WINDOWS\$NtUninstallKB954156_WM9L$
    2008-11-04 11:09:59 ----N---- C:\WINDOWS\readme.txt
    2008-11-04 10:32:41 ----D---- C:\Program Files\Novatix
    2008-11-04 10:32:02 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
    2008-11-04 10:30:02 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Hemera
    2008-11-04 10:15:57 ----D---- C:\WINDOWS\system32\windows media
    2008-11-04 10:14:53 ----HD---- C:\WINDOWS\msdownld.tmp
    2008-11-04 10:14:43 ----D---- C:\Program Files\Windows Media Components
    2008-11-03 16:18:23 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\3D-Album-PS
    2008-11-03 16:15:39 ----D---- C:\WINDOWS\system32\vscrsaver
    2008-11-03 16:15:39 ----A---- C:\WINDOWS\system32\vaesaver.dll
    2008-11-03 16:15:29 ----A---- C:\WINDOWS\system32\vaengine.dll
    2008-11-03 16:15:28 ----D---- C:\Program Files\visviva
    2008-11-03 16:14:47 ----D---- C:\Program Files\3D-Album-TR
    2008-10-30 17:40:23 ----D---- C:\WINDOWS\Sun
    2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\javaws.exe
    2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\javaw.exe
    2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\java.exe
    2008-10-30 17:30:09 ----A---- C:\WINDOWS\system32\deploytk.dll
    2008-10-30 17:29:27 ----D---- C:\Program Files\Java
    2008-10-30 17:13:32 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Sun
    2008-10-25 14:43:04 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Alien Skin
    2008-10-25 12:21:34 ----A---- C:\WINDOWS\system32\ASTSRV.EXE
    2008-10-25 12:21:28 ----D---- C:\Program Files\Alien Skin
    2008-10-24 19:01:04 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2008-10-24 11:34:12 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Help
    2008-10-20 10:20:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2008-10-20 10:19:38 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
    2008-10-20 10:19:13 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
    2008-10-20 10:18:39 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
    2008-10-20 10:17:36 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
    2008-10-13 11:20:50 ----D---- C:\Program Files\Common Files\Control Panels
    2008-10-13 11:12:14 ----D---- C:\Documents and Settings\All Users\Application Data\ALM
    2008-10-13 10:37:47 ----D---- C:\Program Files\QuickTime
    2008-10-13 10:34:35 ----A---- C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
    2008-10-13 10:34:35 ----A---- C:\WINDOWS\system32\NPSWF32.dll
    2008-10-13 10:18:07 ----D---- C:\Program Files\Bonjour
    2008-09-30 16:43:34 ----A---- C:\WINDOWS\system32\msxml4.dll
    2008-09-30 10:18:35 ----A---- C:\WINDOWS\system32\cdintf250.dll
    2008-09-30 10:11:38 ----D---- C:\Program Files\Intuit
    2008-09-30 10:11:38 ----D---- C:\Program Files\Common Files\Intuit
    2008-09-30 10:11:38 ----D---- C:\Documents and Settings\All Users\Application Data\Intuit
    2008-09-30 10:07:41 ----D---- C:\Program Files\Common Files\SWF Studio
    2008-09-29 17:34:38 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\BonkEnc
    2008-09-29 17:17:09 ----D---- C:\Program Files\BonkEnc
    2008-09-17 15:29:24 ----A---- C:\WINDOWS\Latin 8 Font Scrolling LED Display Uninstall Log.txt
    2008-09-17 14:36:27 ----D---- C:\WINDOWS\Latin 8 Font Scrolling LED Display
    2008-09-17 14:36:27 ----D---- C:\Program Files\Latin 8 Font Scrolling LED Display
    2008-09-17 14:36:19 ----A---- C:\WINDOWS\Latin 8 Font Scrolling LED Display Setup Log.txt
    2008-09-16 09:45:30 ----D---- C:\WINDOWS\system32\SoftwareDistribution
    2008-09-13 13:44:34 ----D---- C:\WINDOWS\Minidump
    2008-09-12 18:49:20 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\LogoMaker
    2008-09-12 13:48:24 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\COWON
    2008-09-12 13:45:58 ----D---- C:\Program Files\Common Files\COWON
    2008-09-12 13:45:57 ----D---- C:\Program Files\JetAudio
    2008-09-12 13:43:58 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\InstallShield
    2008-09-11 18:00:19 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\vxblock.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxwave.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxsfs.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxmas.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxinsa64.exe
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxhpinst.exe
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxdrv.dll
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxcpya64.exe
    2008-09-08 14:36:58 ----N---- C:\WINDOWS\system32\pxafs.dll
    2008-09-08 14:36:57 ----N---- C:\WINDOWS\system32\px.dll
    2008-09-08 14:36:53 ----D---- C:\Program Files\Winamp
    2008-09-08 14:36:53 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Winamp
    2008-09-03 15:16:39 ----D---- C:\Program Files\Trend Micro
    2008-09-02 12:48:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$

    ======List of files/folders modified in the last 3 months======

    2008-12-01 11:22:45 ----D---- C:\WINDOWS\Temp
    2008-12-01 11:22:44 ----D---- C:\Program Files\Common Files\Symantec Shared
    2008-12-01 11:22:31 ----D---- C:\WINDOWS\Prefetch
    2008-12-01 11:05:06 ----D---- C:\Program Files\Mozilla Firefox
    2008-12-01 10:36:23 ----A---- C:\WINDOWS\win.ini
    2008-12-01 10:36:22 ----SHD---- C:\WINDOWS\Installer
    2008-12-01 10:36:16 ----D---- C:\WINDOWS\system32
    2008-12-01 10:24:50 ----AD---- C:\WINDOWS
    2008-12-01 10:24:45 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2008-12-01 10:24:38 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-11-29 18:53:32 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-11-29 15:05:33 ----HD---- C:\WINDOWS\inf
    2008-11-29 15:05:33 ----D---- C:\WINDOWS\Help
    2008-11-28 18:37:39 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Corel
    2008-11-27 11:45:49 ----A---- C:\WINDOWS\NeroDigital.ini
    2008-11-21 11:00:34 ----RD---- C:\Program Files
    2008-11-21 10:55:35 ----SD---- C:\WINDOWS\Downloaded Program Files
    2008-11-20 19:00:39 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
    2008-11-20 15:59:27 ----D---- C:\WINDOWS\system32\drivers
    2008-11-17 09:53:35 ----D---- C:\WINDOWS\WinSxS
    2008-11-13 18:37:45 ----A---- C:\WINDOWS\imsins.BAK
    2008-11-13 18:37:35 ----HD---- C:\WINDOWS\$hf_mig$
    2008-11-05 10:12:29 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-11-04 11:16:54 ----D---- C:\Program Files\Common Files\Ulead Systems
    2008-11-04 11:09:37 ----D---- C:\Documents and Settings\All Users\Application Data\Ulead Systems
    2008-11-04 10:32:02 ----D---- C:\Program Files\Common Files
    2008-11-04 10:15:57 ----D---- C:\WINDOWS\RegisteredPackages
    2008-11-04 10:15:53 ----D---- C:\WINDOWS\system32\CatRoot
    2008-11-04 10:13:39 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Ulead Systems
    2008-11-04 10:11:47 ----D---- C:\Program Files\Ulead Systems
    2008-11-04 08:10:25 ----A---- C:\WINDOWS\system32\MRT.exe
    2008-11-03 13:45:40 ----A---- C:\WINDOWS\Iedit_.INI
    2008-11-03 11:18:39 ----RSD---- C:\WINDOWS\Fonts
    2008-10-25 14:32:53 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
    2008-10-25 14:31:56 ----D---- C:\Documents and Settings\Hudson Ong\Application Data\Adobe
    2008-10-20 14:49:23 ----D---- C:\Program Files\Internet Explorer
    2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
    2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
    2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
    2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
    2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wups2.dll
    2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
    2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
    2008-10-16 14:09:40 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
    2008-10-16 14:08:58 ----A---- C:\WINDOWS\system32\wups.dll
    2008-10-16 14:07:44 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
    2008-10-16 14:07:14 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
    2008-10-16 14:06:48 ----A---- C:\WINDOWS\system32\muweb.dll
    2008-10-16 14:06:48 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
    2008-10-16 14:06:48 ----A---- C:\WINDOWS\system32\mucltui.dll
    2008-10-16 00:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll
    2008-10-15 10:31:32 ----D---- C:\Program Files\Business-in-a-Box
    2008-10-13 11:28:57 ----D---- C:\Program Files\Common Files\Adobe
    2008-10-13 11:25:15 ----D---- C:\Program Files\Adobe
    2008-10-04 01:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
    2008-10-02 14:01:13 ----D---- C:\Documents and Settings
    2008-09-30 11:38:36 ----SD---- C:\Documents and Settings\Hudson Ong\Application Data\Microsoft
    2008-09-29 16:46:20 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
    2008-09-13 14:23:42 ----SHD---- C:\System Volume Information
    2008-09-13 14:23:42 ----D---- C:\WINDOWS\system32\Restore
    2008-09-10 09:14:56 ----N---- C:\WINDOWS\system32\msxml6.dll
    2008-09-05 01:15:04 ----A---- C:\WINDOWS\system32\msxml3.dll

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2004-10-08 35840]
    R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
    R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
    R1 SRTSP;SRTSP; C:\WINDOWS\System32\Drivers\SRTSP.SYS [2008-01-31 279088]
    R1 SRTSPX;SRTSPX; C:\WINDOWS\System32\Drivers\SRTSPX.SYS [2008-01-31 43696]
    R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2008-06-13 184240]
    R2 CO_Mon;CO_Mon; \??\C:\WINDOWS\system32\drivers\CO_Mon.sys []
    R2 OsaFsLoc;OsaFsLoc; \??\C:\WINDOWS\System32\drivers\OsaFsLoc.sys []
    R2 osaio;osaio; \??\C:\WINDOWS\System32\drivers\osaio.sys []
    R2 SIODRV;SIODRV; \??\C:\WINDOWS\System32\drivers\SIODRV.SYS []
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-02-08 3846016]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
    R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [2003-04-11 51024]
    R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [2003-04-11 16080]
    R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [2003-04-11 21456]
    R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081130.023\NAVENG.SYS []
    R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081130.023\NAVEX15.SYS []
    R3 NTIDrvr;Upper Class Filter Driver; C:\WINDOWS\System32\DRIVERS\NTIDrvr.sys [2008-05-17 6144]
    R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
    R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
    R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\System32\DRIVERS\SMBios.sys [2003-11-03 36484]
    R3 smbusp;Intel(R) SMBus 2.0 Driver; C:\WINDOWS\System32\DRIVERS\intelsmb.sys [2005-03-15 21248]
    R3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2008-06-13 13616]
    R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
    R3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2008-06-13 96432]
    R3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2008-06-13 38576]
    R3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\ipsdefs\20081127.002\SymIDSCo.sys []
    R3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
    R3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2008-06-13 37424]
    R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2008-06-13 22320]
    R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
    R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-14 25856]
    R3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-14 15104]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
    S3 COH_Mon;COH_Mon; \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys []
    S3 exdisk;Express Disk Service; C:\WINDOWS\System32\DRIVERS\exdisk.sys []
    S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2004-06-28 42752]
    S3 SRTSPL;SRTSPL; C:\WINDOWS\System32\Drivers\SRTSPL.SYS [2008-01-31 317616]
    S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280]
    S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 ASTSRV;Nalpeiron Licensing Service; C:\WINDOWS\system32\ASTSRV.EXE [2008-05-19 57344]
    R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2008-02-09 238968]
    R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
    R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
    R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
    R2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
    R2 iHCService;Intel(R) Desktop Utilities Service; C:\Program Files\Intel\IDU\IDUServ.exe [2005-04-29 1302016]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-30 152984]
    R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
    R2 LiveUpdate Notice;LiveUpdate Notice; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
    R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-06-12 654848]
    R3 Symantec Core LC;Symantec Core LC; C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [2008-06-04 1245064]
    S3 Adobe Version Cue CS3;Adobe Version Cue CS3; C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe [2007-03-20 153792]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
    S3 comHost;COM Host; C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [2007-08-22 55640]
    S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2008-08-04 3220856]
    S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.exe [2003-04-11 65795]

    -----------------EOF-----------------

    Regards,
    Chayienne
     
  11. 2008/12/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Log looks fine. :)
    A couple of entries that do nothing to remove though. Please scan with HijackThis and place a check next to the following entries, then click Fixed Checked.

    O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')

    You can exit HijackThis once it processes those.

    You can now delete Flash_Disinfector.exe, RSIT.exe and the C:\rsit folder.
    Open MBAM and remove any items in quarantine.
    Run ATF Cleaner again to clear temps and empty the recycle bin.

    If you're satisfied that the computer is working properly, I recommend you clear the System Restore points.

    Clear past system restore points and create a new one.
    Right click My Computer and select Properties. On the System Restore tab, check the box to turn System Restore off. Click Apply. Now, uncheck the box and click Apply to turn System Restore back on. Click OK, then OK to close the System Properties dialog.

    Verify a new restore point was created.
    Click Start>All Programs>Accessories>System Tools>System Restore
    Select 'Restore my computer to an earlier time', then click next.
    You should have a newly created System Checkpoint available. If so, click Cancel. If not, click Back and select 'Create a restore point' then click Next. Give the restore point a name and click next.


    Let me know if any issues remain.
     
  12. 2008/12/03
    chayienne

    chayienne Inactive Thread Starter

    Joined:
    2008/11/20
    Messages:
    6
    Likes Received:
    0
    Thank you very much for all your help. My PC is working fine now.

    Regards,
    Chayienne
     
  13. 2008/12/03
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Glad to hear it, and happy I could help. You're most welcome. Geri has posted some very helpful information and recommendations regarding future protection in the following link.

    http://www.windowsbbs.com/showthread.php?t=67958

    Surf safe! :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.