Your daughter's laptop has quite a lot of malware running around in there.
The problem with these infections is that they cause a lot of damage. Even if we can clean the malware off your system, I cannot guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognize and logs won't show.
After cleaning the malware, you can still get errors afterwards because of the damage.
We can try to clean this up and do what we can, but keep in mind that we may not be able to solve ALL problems this malware already caused.
This allows hackers to steal critical system information and Download and Execute files.
I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
Though the Trojan has been identified and can be killed, because of its backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:
How to report ID theft, fraud, drive-by installs, hijacking and malware?
http://www.dslreports.com/faq/10451
I'd like to try to clean it up if possible, and not to much of a pain.
There is some sensitive material, unfortunately that may already be compromised.....I tunes account, paypal account, student information.
First order...how can I make sure this unit is offline? I can't seem to shut down the built in WIFI, and the events log appears to be showing continuing attack attemps. It's running off of a broadband wireless home network currently, as are 2 other laptops and the desktop. And now I'm concerned about the desktop...I keep gettting warnings about security certificate issues from sights I normally have no problems with. So now I'm almost half afraid to access potentially comprimised accounts (paypal etc.) to change passwords. I just ran a complete scan on this machine, and came up clear, but when trying to access sights that require a password, I get the certificate security warning page suggesting not to proceed.
Now I'm worried. :(
If reformatting is easier or safer, I would probably go that route. I don't have an installation disk and no idea how to do that either. She's got alot of work on there that she would probably lose then, correct? I know that would kill her, so I'd like to try clean up first.
I tunes account, paypal account, student information.
That would be enough to scare me!
As far as the WIFI, there should be a way to disconnect. Typically, you would go to your WIFI icon by the clock. Rt-click "View Available Wireless Networks". When that window comes up, click the DISCONNECT button for the wireless network that the computer is on.
Considering the malware on there, I cannot guarantee that our fixes will go smoothly, so it would be good for your daughter to start backing up her important documents now.
Well, I've backed up as much of the data that I could. It won't allow me access to delete any programs, even in safe mode as administrator. This, BTW, is the only way I can get to the control panel now.
Are there any programs left that will interfere with the attempted fix? Will I be able to download the necessary cleaning programs to a disk or traveldrive, or will I have to hook the infected machine back up to the internet?
If we can get it cleaned up, and the OS isn't to whacked, she'll just use it for non-critical stuff. No more sensitive info.
Again, thanks much for your help.
Ready when you are.
FWIW; I just canceled the credit card associated with the above mentioned accounts a couple weeks ago due to a $200+ charge that wasn't mine. Basically this was the only card I use for internet purchases, and luckily I haven't had the time to update any online accounts with the replacement card yet.
Are there any programs left that will interfere with the attempted fix? Will I be able to download the necessary cleaning programs to a disk or traveldrive, or will I have to hook the infected machine back up to the internet?
We'll just a do a little at a time and see how things go. You will need to download our tools from the internet. Therefore, it would be easiest to use that machine, but if you do not want to do that, you will need to download them to a USB stick or CD and transfer them to the infected machine.
I'll try to fix the password stealer first, so that can use the infected machine online.
I see the service for McAfee Security Center, but I do not see it in the running processes. What happened to the anti-virus on that computer?
Open a command prompt:
Click start >run > type cmd and hit Enter
Into the command window type the following commands one at a time, hit Enter AFTER EACH LINE
sc stop ZZZsvc_lich sc delete ZZZsvc_lich
Delete this file:
C:\
lich.exe
Double click
SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in
Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.
Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back here with any other logs requested
Your HijackThis is outdated.
Please download HJT Installer for version 2.02 from
Here to your desktop.
If not available use this alternate link:
Here
Click the Download button. When the Trend Micro HJT install box appears, double click on the HJTInstall.exe. Click on Install.
It will be installed by default here: C:\Program Files\Trend Micro\HijackThis.
A shortcut to the application will also be placed on your Desktop.
The program will open automatically after installation.
You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder. The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.
The first time you open HijackThis, check the Main Menu button at the bottom center. When the main menu appears check the box "Show this window when I start HijackThis".
Click on "Do a system scan and save logfile." When the log pops up in Notepad, copy and paste that file back here along with the log from SDFix.
"ErrorControl"=dword:00000001
"Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations"=str(7):"\x6264\4\x7fa8\36\x148;\20\0\xe020|\x6020|\xa020|\xffc0\xffffsystem32\DRIVERS\USBSTOR.SYS\0\0\xfff8\xffff\x718;\xffe0\xffff\x6b76\a\32\0\x8c28?\1\0\1D\x6553\x7672\x6369e\xfff8\xffff\x1078;\xffd8\xffff\x6b76\17\32\0\x87a0?\a\0\1\0\x6544\x6570\x646e\x6e4f\x6553\x7672\x6369e\xffe8\xffffdrvmcdb\0\0\0\xffa0\xffff\x6b6e \xbcb4\xb428\xa21b\x1c5\0\0\xfc58:\0\0\0\0\xffff\xffff\xffff\xffff\5\0\xf2b8:\x218\0\xffff\xffff\0\0\0\0,\0\34\0\0\0\n\0\x6150\x6172\x656d\x6574\x7372\0\0\0\xffd0\xffff\x6b76\24\4\x8000\0\0\4\0\1\0\x6f43\x6e6e\x6365\x4d74\x6c75\x6974\x6c70\x5065\x726f\x7374\0\0\xffd0\xffff\x6b76\25\4\x8000d\0\4\0\1\0\x654b\x6279\x616f\x6472\x6144\x6174\x7551\x7565\x5365\x7a69e\0\xffd0\xffff\x6b76\26\34\0\xff50:\1\0\1\0\x654b\x6279\x616f\x6472\x6544\x6976\x6563\x6142\x6573\x614e\x656d\0\xffe0\xffffKeyboardClass\0\xffd0\xffff\x6b76\24\4\x8000\3\0\4\0\1\0\x614d\x6978\x756d\x506d\x726f\x7374\x6553\x7672\x6369\x6465\0\0\xffd0\xffff\x6b76\24\4\x8000\1\0\4\0\1\0\x6553\x646e\x754f\x7074\x7475\x6f54\x6c41\x506c\x726f\x7374\0\0\xffa8\xffff\x6b6e \x52ee_\x4514\x1c8\0\0\x6690\35\1\0\1\0\xf640:\x63d8\x8002\5\0\x8478\36\x218\0\xffff\xffff\20\0\0\0\30\0D\0\x8a\0\6\0\x6d6b\x7869\x7265\0\xffd8\xffff\x6b76\17T\0\xd9b8E\1\0\1\0\x6e45\x6d75\x7250\x706f\x6150\x6567\x33732\xffd8\xffff\x6b76\r\4\x8000\xa8be\0\4\0\0011\x6844\x7063\x6552\x7274\x5479\x6d69e7\xffe0\xffff\x6b76\5L\0\x3d60N\1\0\1\0\x4c43\x4953D\0\xfff0\xffff\3\0\0@\xd740@\xffd8\xffff\x6b76\n<\0\xad38?\1\0\1e\x6544\x6976\x6563\x6544\x6373\x7672\x6369e\xffc8\xffffRoot\MS_NDISWANIP\0000\0\0\0\0\xffc0\xffffRoot\MS_PPPOEMINIPORT\0000\0\0\0\0 \0LegacyDriver\0\0\xffa8\xffff\x6b6e \xd61a4\x6585\x1c6\0\0\xffd0:\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xf110:\x74f0\20\xffff\xffff\0\0\0\0\20\0\xa8\0\0\0\b\0\x6553\x7563\x6972\x7974\xffe0\xffff\x6b76\b\xa8\0\x1e0;\3\0\1\0\x6553\x7563\x6972\x7974\xff50\xffff\1\x8014\x90\0\x9c\0\24\0000\0\2\34\1\0\x8002\24\x1ff\17\x101\0\0\x100\0\0\2`\4\0\0\24\x1fd\2\x101\0\0\x500\22\0\0\30\x1ff\17\x201\0\0\x500 \0\x220\0\0\24\x18d\2\x101\0\0\x500\v\0\0\30\x1fd\2\x201\0\0\x500 \0\x223\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\0\0\xffa8\xffff\x6b6e \xd9ea\xe443\x4513\x1c8\0\0\x6690\35\0\0\1\0\xffff\xffff\x58a0\x8000\5\0\x7428\e\x218\0\xffff\xffff\b\0\0\0\30\0\n\0\x8b\0\6\0\x534b\x6365\x4444\0\xffd0\xffffRoot\MS_PSCHEDMP\0000\0\xffd8\xffff\x6b76\f\x114\0\x7d70=\1\0\1!\x7953\x626d\x6c6f\x6369\x694c\x6b6e\W\xffe0\xffff\x6b76\0034\0hD\1\0\1\0\x664dg\0\0\xffe0\xffff\x6b76\4\4\x8000\20\0\4\0\1E\x7954\x6570\x05f0F\xffd8\xffff\x6b76\16,\0\xfd00:\1\0\1\xcc20\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\x6696\xffa0\xffff\x6b6e \xd9ea\xe443\x4513\x1c8\0\0\x6690\35\6\0\1\0\x1f98;\x59b8\x8000\a\0\x2330"\x218\0\xffff\xffff&\0\0\0\30\0\x1da\0\x8c\0\f\0\x616c\x6d6e\x6e61\x6573\x7672\x7265\0\0\xffd8\xffff\x6b76\f\xd0\0\x5738=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffd0\xffffRoot\MS_PSCHEDMP\0002\0\xffd8\xffff\x6b76\f\xd0\0\x3020=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffe0\xffff\x6b76\0034\0\x86a8?\1\0\1\0\x664dg\0\0\xffe0\xffff\x6b76\a\n\0\xf9b0:\1\0\1=\x6553\x7672\x6369e\xffd8\xffff\x6b76\0162\0\x608;\1\0\1\23\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\23\xffe0\xffffLocalSystem\0\0M\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\0\x6f43\x666e\x6769\x6c46\x6761\x6c73\0\0\xffd8\xffff\x6b76\16,\0\x430;\1\0\1w\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\r\xfff8\xffff\x1780;\xffe0\xffff\x6b76\3J\0\x9540L\1\0\1\0\x664dg\0\0\xffd8\xffff\x6b76\vb\0\x4c20E\1\0\1n\x6944\x7073\x616c\x4e79\x6d61efP\xffd8\xffff\x6b76\f\xd6\0\x3208=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xfff8\xffff\x2120;\xfff8\xffff\x1e30;\xffe0\xffff\0\0\0\0\0\0\1\0\xade0\b\1\0\x3e8\0\xffc8\xffffRoot\MS_PTIMINIPORT\0000\0\0\xfff8\xffff\x1988;\xffd8\xffff\x6b76\17\4\x8000\0\0\4\0\1:\x6844\x7063\x6552\x7274\x5379\x6174\x7574s\xffc8\xffff\x6b76\e\xe8b2\0\xfd90:\a\0\1\37\x6550\x646e\x6e69\x4667\x6c69\x5265\x6e65\x6d61\x4f65\x6570\x6172\x6974\x6e6fsMA\b\0x;\xffe8\xffffdisk.inf\0&\xffb0\xffff\x9180\0\x4338\0\xe4b8\1\xe670\1\xe0b0\16\xe230\16\x9390\25\xd8f0\26\x9348\25\xd710\26\xd6b8\26\xd768\26\xd738\26\xd7d8\26\xd850\26\xd7a0\26\xd810\26\x8258(\x03401\xffd8\xffff\x6b76\f\xc0\0\x3418=\1\0\1F\x7953\x626d\x6c6f\x6369\x694c\x6b6eDE\xfff8\xffff\x1d48;\xffd8\xffff\x6b76\16\4\x8000\a\0\4\0\1C\x7954\x6570\x5373\x7075\x6f70\x7472\x6465t\xfff0\xffff\x80f\xf09\x908\xf00\b\x293d\xffe0\xffff\x6b76\5\x28e\0\x6308K\a\0\1\0\x6f52\x7475eu\xfff8\xffff\x17a8;\xff98\xffff\x6b6e \x16b4\xb509\xa280\x1c5\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\0\0\xffff\xffff\x218\0\xffff\xffff\0\0\0\0\0\0\0\0\0\0\23\0\x7541\x6f74\x7574\x656e\x5064\x7261\x6d61\x7465\x7265s\0\0\xffa0\xffff\x6b6e \xae24\x1883\x6992\x1c6\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\17\0\xb50;\x218\0\xffff\xffff\0\0\0\0H\0\xbc\0\1\0\17\0\x6544\x6166\x6c75\x5374\x6365\x7275\x7469y\xff58\xffff\1\x8004\x8c\0\x98\0\0\0\24\0\2x\5\0\0\30\3\17\x201\0\0\x500 \0\x220\0\0\30\3\17\x201\0\0\x500 \0\x225\0\0\30\3\17\x201\0\0\x500 \0\x227\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xffd0\xffff\x6b76\27|\0\x948;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x4165\x6d64\x6e69\x6f43\x6e6e\x6365t\xff80\xffff\1\x8004d\0p\0\0\0\24\0\2P\3\0\0\30\3\17\x201\0\0\x500 \0\x220\0\0\30\3\17\x201\0\0\x500 \0\x225\0\0\30\3\17\x201\0\0\x500 \0\x227\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xffd0\xffff\x6b76\21\x90\0\x71f0F\3\0\1\2\x7253\x7376\x6376\x6553\x7373\x6f69\x496e\x666e\x16f\2\x201\0\xffd0\xffff\x6b76\24x\0\xa28;\3\0\1\0\x7253\x7376\x6376\x7453\x7461\x7369\x6974\x7363\x6e49\x6f66\0\0\xff80\xffff\1\x8004`\0l\0\0\0\24\0\2L\3\0\0\30\1\17\x201\0\0\x500 \0\x220\0\0\30\1\17\x201\0\0\x500 \0\x225\0\0\24\1\0\x101\0\0\x200\0\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\0\0\xffc8\xffff\x6b76\34\4\x8000\1\0\4\0\1\0\x6e41\x6e6f\x6d79\x756f\x4473\x7365\x7263\x7069\x6f74\x7372\x7055\x7267\x6461\x6465\0\0\xffd8\xffff\x6b76\16"\0\x1e58;\1\0\0013\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\0\xfff0\xffff\xf44\x96\0\x12c\x1f40\0\xffc8\xffff\x6b76\34\4\x8000\0\0\4\0\1\0\x7250\x7665\x6f69\x7375\x6e41\x6e6f\x6d79\x756f\x5273\x7365\x7274\x6369\x6974\x6e6f\0\0\xffc0\xffff\x12b0;\xc70;\xca0;\xcc8;\xcf8;\xf40;\x1018;\x1048;\x10a0;\x918;\x9f8;\xaa8;\xb18;\x9c8;\x89c8F\xfff8\xffff\xae0;\xffe8\xffff\x686c\2\x0908F\xea98\x6e7f\x09b0F\xe2d0\xe465\xff40\xffff\1\x8004\xa0\0\xac\0\0\0\24\0\2\x8c\6\0\0\30\27\17\x201\0\0\x500 \0\x220\0\0\30\27\17\x201\0\0\x500 \0\x225\0\0\24\27\17\x101\0\0\x500\22\0\0\30\3\0\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\0\0\xffd0\xffff\x6b76\23\xa4\0\xd50;\3\0\1\0\x7253\x7376\x6376\x7254\x6e61\x7073\x726f\x4574\x756em\0\0\xffd8\xffff\x6b76\20\x94\0\xdf8;\3\0\1\0\x7253\x7376\x6376\x6f43\x6e6e\x6365\x6974\x6e6f\xffd0\xffff\x6b76\24d\0\xe90;\3\0\1\0\x7253\x7376\x6376\x6553\x7672\x7265\x6944\x6b73\x6e45\x6d75\0\0\xffd8\xffff\x6b76\n|\0\x12d8;\3\0\1\0\x7253\x7376\x6376\x6946\x656c\0\0\0\xffe0\xffff\x6b76\6\x432\0\xd900L\a\0\1\0\x7845\x6f70\x7472i\xfff0\xffff\4\0\0@\xc208@\xff58\xffff\1\x8004\x8c\0\x98\0\0\0\24\0\2x\5\0\0\30\27\17\x201\0\0\x500 \0\x220\0\0\30\27\17\x201\0\0\x500 \0\x225\0\0\24\27\17\x101\0\0\x500\22\0\0\30\3\0\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x500\v\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xff68\xffff\1\x8004|\0\x88\0\0\0\24\0\2h\4\0\0\30\1\17\x201\0\0\x500 \0\x220\0\0\30\1\17\x201\0\0\x500 \0\x225\0\0\30\1\0\x201\0\0\x500 \0\x226\0\0\30\1\0\x201\0\0\x500 \0\x223\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xff98\xffff\1\x8004L\0X\0\0\0\24\0\28\2\0\0\30\1\17\x201\0\0\x500 \0\x220\0\0\30\1\17\x201\0\0\x500 \0\x225\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xffd8\xffff\x6b76\16"\0\x1758;\1\0\1t\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563o\xffe0\xffff192.168.1.1\0\0\0\xffd0\xffff\x6b76\23\xa4\0\xf70;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x4665\x6c69\x4965\x666eo\0\0\xff58\xffff\1\x8004\x8c\0\x98\0\0\0\24\0\2x\5\0\0\30\23\17\x201\0\0\x500 \0\x220\0\0\30\23\17\x201\0\0\x500 \0\x225\0\0\30\23\17\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xffd0\xffff\x6b76\24\xbc\0\x1110;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x5065\x6972\x746e\x6e49\x6f66\0\0\xffd0\xffff\x6b76\24\xa4\0\x11d0;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x4165\x6d64\x6e69\x6e49\x6f66\0\0\xffd8\xffff\x6b76\f\xd8\0\x3718=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffd0\xffff\x6b76\22\xa4\0\x870;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x4365\x6e6f\x656e\x7463\0\0\0 \0\xe4f8:\xe9b8:\x858=\xfd90:\xb850C\xe558C\xe800C\xffe0\xffff\x6b76\4\x362\0\x13c0;\a\0\1a\x6942\x646eis\xff40\xffff\1\x8004\xa4\0\xb0\0\0\0\24\0\2\x90\6\0\0\30\23\17\x201\0\0\x500 \0\x220\0\0\30\23\17\x201\0\0\x500 \0\x225\0\0\30\23\17\x201\0\0\x500 \0\x226\0\0\30\23\17\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xff58\xffff\1\x8004\x8c\0\x98\0\0\0\24\0\2x\5\0\0\30\23\17\x201\0\0\x500 \0\x220\0\0\30\2\0\x201\0\0\x500 \0\x225\0\0\30\2\0\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xfff8\xffff\x1d70;\xffd0\xffff\x6b76\27\4\x8000\1\0\4\0\1\0\x6e65\x6261\x656c\x6573\x7563\x6972\x7974\x6973\x6e67\x7461\x7275e\xffd8\xffff\x6b76\20\xb8\0\xbb0;\3\0\1\0\x7253\x7376\x6376\x6f43\x666e\x6769\x6e49\x6f66\xff80\xffff\1\x8004d\0p\0\0\0\24\0\2P\3\0\0\30\21\17\x201\0\0\x500 \0\x220\0\0\30\21\17\x201\0\0\x500 \0\x225\0\0\30\21\17\x201\0\0\x500 \0\x223\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xfff0\xffff011@\xc7a0@\xffa8\xffff\x6b6e \x242eX\xcd60\x1c6\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\3\0\xee78\32\x218\0\xffff\xffff\0\0\0\0\f\0\x432\0\2\0\a\0\x694c\x6b6e\x6761e\xfc98\xffff\Device\NetbiosSmb\0\Device\NetBT_Tcpip_{A63D250C-D9FF-4DF6-8DC1-C8F98F2E7539}\0\Device\NetBT_Tcpip_{B6D36F25-35E9-491D-91AF-34E4B0954885}\0\Device\NetBT_Tcpip_{683D9BA7-E222-4B49-8C13-B1D8F48C39E7}\0\Device\NetBT_Tcpip_{B1A579A3-BC60-43D9-BB6C-798D05FA638C}\0\Device\NetBT_Tcpip_{61E68846-AE27-44B7-B0FB-0C629F393B8A}\0\Device\NetBT_Tcpip_{29B39846-0902-49E5-B96A-2F1FC54E9A72}\0\Device\NetBT_Tcpip_{2F9FBC39-C724-4E7B-AEFD-EDFE1FAC9BF8}\0\0t\xffd0\xffff\x6b76\21\4\x8000\x5113\x476c\4\0\1E\x654c\x7361\x4f65\x7462\x6961\x656e\x5464\x6d69\x7f65E\xae00E\xffd8\xffffRoot\SYSTEM\0000\0\0\xffd8\xffff\x6b76\16"\0\x17d0;\1\0\1\0\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\0\xffd8\xffff\x6b76\16f\0\x38a8=\1\0\1s\x6544\x6976\x6563\x6e49\x7473\x6e61\x65638\xffd8\xffffRoot\SYSTEM\0000\0q\xffd0\xffff\x5288:\x8de0:\x7580:\x9828:\x8ae8:\x8f68:\x98e0:\xa7e0:\x52a8:\xe460:\xe2c0:\xffe0\xffff\x6b76\b\b\0\xbaa0\35\3\0\1\0\x3031\x4232\x3530\x3032\xffe0\xffff\x6b76\6\4\x8000\1\0\4\0\1.\x654c\x6167\x7963\0\xffd8\xffff\x6b76\n\16\0\x4f68\37\1\0\1\0\x6544\x6976\x6563\x6544\x6373\x4e50F\0\xffc0\xffffsystem32\DRIVERS\ipnat.sys\0\0\0\0\xffd8\xffff\x6b76\f\xd8\0\x5130=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffe0\xffff\xed80"\xe3c0:\xed70:\x1b88;\xf338:\xa8;\L\xffe8\xffffMicrosoft\0\xffa8\xffff\x6b6e \xf110\xe4d9\x43e1\x1c8\0\0\x5748\20\1\0\0\0\xf2a0:\xffff\xffff\n\0\x3cd0D\x218\0\xffff\xffff\20\0\0\0\36\0n\0\\0\a\0\x6865\x6552\x7663\x4d72\xffd8\xffff\x6b76\f\x114\0\x65f0=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\xff48+\xffd8\xffff\xcc68\32\xcd58\32\xcc28\32\xcdb8\32\xc580\32\xce38\32\x7418"\x7ac8"\x3bc0!\xfff0\xffff\x2ee\x02eed\5\xc746@\xffe0\xffff\x6b76\2\4\x8000\x9003\x44f7\4\0\1\0\x3154\0\x21d4&\xffd8\xffff\x6b76\v<\0\x1210D\1\0\1r\x6944\x7073\x616c\x4e79\x6d61\x6565on\xffe0\xffff\x6b76\5\4\x8000\3\0\4\0\1c\x7453\x7261\x6b74\4\xffd8\xffff\x6b76\n\30\0\x1a78;\1\0\1\0\x6544\x6976\x6563\x6544\x6373e\0\0\xffe0\xffffZZZdrv_lich\0te\xffd8\xffff\x6b76\v<\0\xe580C\1\0\1:\x6944\x7073\x616c\x4e79\x6d61e\x1728;\xffc0\xffff\x6b76!\4\x8000\xffff\xffff\4\0\1g\x7355\x7265\x614d\x7473\x7265\x6544\x6976\x6563\x6954\x696d\x676e\x6f4d\x6564\x6c41\x6f6c\x6577d\WI\xfff8\xffff\x318;\xffa0\xffff\x6b6e \x3258\xfacb\x4513\x1c8\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\f\0\x46e0M\x218\0\xffff\xffff\0\0\0\0000\0\x90\0\3\0\n\0\x6170\x6172\x656d\x6574\x7372\0\0\0\xffe0\xffff\x6b76\5\32\0\xfdd0<\1\0\1v\x6c43\x7361\x7973e\xffe0\xffff\x6b76\5\32\0\xf278:\1\0\1E\x6c43\x7361\x6973\x7974\xffc8\xffffCOM+ System Application\0di\xffa8\xffff\x6b6e \xf20\xa0fe\xc11f\x1c7\0\0\x5748\20\1\0\0\0\xfae8:\xffff\xffff\6\0\x5f50D\x218\0\xffff\xffff\20\0\0\0\30\0\x82\0\x15b\0\6\0\x7557\x6664\x6452t\xffc0\xffffsystem32\DRIVERS\wudfrd.sys\0ca\xffd8\xffff\x6b76\v\x82\0\x1ca0;\1\0\1n\x6944\x7073\x616c\x4e79\x6d61e\x6b76\16\xff78\xffffWindows Driver Foundation - User-mode Driver Framework Reflector\0\t\xffe0\xffff\x6b76\b\xa8\0\x5e08D\3\0\1\x7461\x6553\x7563\x6972\x7974\xffd8\xffff\x6b76\16\x9a\0\x4940=\1\0\1\0\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\0\xffd8\xffff\x6b76\f\xfa\0\x6b20=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffe0\xffff\xa408\36\x5308\37\x5688\37\x5548\37\x1eb8 \x9e100\0\0\xffd8\xffff\x6b76\r\2\x8000\0\0\a\0\1M\x6544\x6570\x646e\x6e4f\x7247\x756f\x6370e\b\0\x670;\xffe0\xffff\x6b76\b\xa8\0\x1ee8;\3\0\1\0\x6553\x7563\x6972\x7974\xffd8\xffff\x6b76\n\30\0\xfe40\34\1\0\1o\x624f\x656a\x7463\x614e\x656d\0Mi\xffd8\xffff\x6b76\f\x100\0\x77a0=\1\0\0016\x7953\x626d\x6c6f\x6369\x694c\x6b6e\x92c0<\xffd8\xffffRoot\SYSTEM\0000\0002\xfff0\xffff011@\xcac8@\xffa8\xffff\x6b6e \x6dba\x93cc\xa281\x1c5\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xf5a8:\x74f0\20\xffff\xffff\0\0\0\0\20\0\xa8\0\4\0\b\0\x6553\x7563\x6972\x7974\xff50\xffff\1\x8014\x90\0\x9c\0\24\0000\0\2\34\1\0\x8002\24\x1ff\17\x101\0\0\x100\0\0\2`\4\0\0\24\x18d\2\x101\0\0\x500\v\0\0\30\x19d\2\x201\0\0\x500 \0\x223\0\0\30\x1ff\17\x201\0\0\x500 \0\x220\0\0\24\x1fd\2\x101\0\0\x500\22\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\0\0\xffc0\xffff\x686c\6\x7a8;\xfb41\xc485\x810;\x55dd\x240d\x1368;\x59b7\x9d4a\x1b08;\xea98\x6e7f\x1e90;\xe2d0\xe465\xe020:\xb4c2\x5f4d\x1e50;#\0\xffd8\xffff\x6b76\nB\0PF\2\0\1e\x6553\x7672\x6369\x4465\x6c6cM\0d\x6268\x6e69\x2000;\x1000\0\0\0\0\0\0\0\0\0\0\0\xffc0\xffffsystem32\DRIVERS\ipsec.sys\0til\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\0\x6f43\x666e\x6769\x6c46\x6761s\0\0\xffc8\xffff\x6b76\34\30\0\xedc0\35\1\0\1>\x6f43\x6f6c\x7275\x7546\x6c6c\x6373\x6572\x6e65\x6f43\x746e\x6172\x7473\x445f\x4645\x56c8>\xffd8\xffff\x6b76\v\32\0\x5098\37\1\0\1o\x6944\x7073\x616c\x4e79\x6d61ee \xffc8\xffffRoot\MS_L2TPMINIPORT\0000\0\xffd8\xffff\x6b76\16\x9a\0\x5970=\1\0\0010\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563<\xffd8\xffff\x6b76\n`\0\x39a0D\1\0\1\0\x6544\x6976\x6563\x6544\x6373\0\0\0\b\0\xa398!\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\a\x6f43\x666e\x6769\x6c46\x6761s\0017\xffc8\xffffFSFilter Infrastructure\0\0\0\xfff0\xffff\17\xf0b\xb00\xf00\b\x4b5f\xffd8\xffff\x6b76\tN\0\x4548E\1\0\1\0\x6c43\x7361\x4773\x4955D\0\0\0\xffa8\xffff{4D36E97D-E325-11CE-BFC1-08002BE10318}\0\x7478\x6e49\x7473\xffa0\xffff\x6b6e \xba9a\x5641\xa281\x1c5\0\0\x7bd0F\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2350;\x218\0\xffff\xffff\0\0\0\0\24\0\\0\0\0\n\0\x6150\x6172\x656d\x6574\x7372are\xffd8\xffff\x6b76\n\\0\x22f0;\2\0\1\26\x6553\x7672\x6369\x4465\x6c6c\26\x7e00\26\xffa0\xffff%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll\0\xfff8\xffff\x22c8;\xffa8\xffff\x6b6e \xd322\x55d8\xa281\x1c5\0\0\x7bd0F\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2480;\x74f0\20\xffff\xffff\0\0\0\0\20\0\xa8\0\1\0\b\0\x6553\x7563\x6972\x7974\xffe0\xffff\x6b76\b\xa8\0\x23d0;\3\0\1a\x6553\x7563\x6972\x7974\xff50\xffff\1\x8014\x90\0\x9c\0\24\0000\0\2\34\1\0\x8002\24\x1ff\17\x101\0\0\x100\0\0\2`\4\0\0\24\x1fd\2\x101\0\0\x500\22\0\0\30\x1ff\17\x201\0\0\x500 \0\x220\0\0\24\x18d\2\x101\0\0\x500\v\0\0\30\x1fd\2\x201\0\0\x500 \0\x223\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0Sy\xfff8\xffff\x23b0;\xffe8\xffff\x686c\2\x2268;\xea98\x6e7f\x2358;\xe2d0\xe465\xffa8\xffff\x6b6e \x5a5a\xb426\xa21b\x1c5\0\0\x6690\35\1\0\0\0\x2858;\xffff\xffff\b\0\x2a40;\x218\0\xffff\xffff\24\0\0\0\36\0\x2e6\0o\0\a\0\x6948\x5364\x7265v\xffd8\xffff\x6b76\17\16\0\x2520;\a\0\1\0\x6544\x6570\x646e\x6e4f\x6553\x7672\x6369e\xffe8\xffffRpcSs\0\0\0\0\0\xfff8\xffff\x2ac8;\xffd8\xffff\x6b76\v\x2e6\0\x2568;\1\0\1\0\x6544\x6373\x6972\x7470\x6f69n\0\0\xfd10\xffffEnables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.\0\0\0\0\xfff0\xffff\x686c\1\x2a68;\xea98\x6e7f\xffd8\xffff\x6b76\v<\0\x2890;\1\0\1\0\x6944\x7073\x616c\x4e79\x6d61e\0\0\xffc0\xffffHuman Interface Device Access\0\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1\0\x7245\x6f72\x4372\x6e6f\x7274\x6c6f\0\0\xfff0\xffffhpn\0\x5518.\xfff8\xffff\x2d70;\xffd8\xffff\x6b76\tZ\0\x2938;\2\0\1\0\x6d49\x6761\x5065\x7461h\0\0\0\xffa0\xffff%SystemRoot%\System32\svchost.exe -k netsvcs\0\0\xffd8\xffff\x6b76\n\30\0\x29c0;\1\0\1\0\x624f\x656a\x7463\x614e\x656d\0\0\0\xffe0\xffffLocalSystem\0\0\0\xffe0\xffff\x6b76\5\34\0\x2bb8;\1\0\1\0\x7247\x756fp\0\xffe0\xffff\x6b76\5\4\x8000\4\0\4\0\1\0\x7453\x7261t\0\xffe0\xffff\x6b76\4\4\x8000 \0\4\0\1\0\x7954\x6570\0\0\xffd8\xffff\x24f8;\x2540;\x2868;\x28d0;\x2910;\x2998;\x2a00;\x2a20;\0\0\xffa0\xffff\x6b6e \x5a5a\xb426\xa21b\x1c5\0\0\x24a0;\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2538;\x218\0\xffff\xffff\0\0\0\0\24\0D\0\0\0\n\0\x6150\x6172\x656d\x6574\x7372\0\0\0\xffd8\xffff\x6
Not sure what happened to my McAffe security suite.....comes free with the Comcast and I've had really good luck with it up to this point....but, yeah, I noticed it's pretty much wiped out.
Had a little trouble with the SDFix D/L on the travel drive...kept getting a "some files are corrupt, CRC failed in SDFix\catchme.exe" but finally got it to work on a cd.
Control panel is back, seems to be running better. Keep getting a small pop up that says just "copying" and a pop up that warns my computer is making copies of files, or something like that.
Anyway here is the HJT log after fix;
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:44:32 PM, on 12/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Bugbatter
3 Apprentice
•
20.5K Posts
0
December 21st, 2007 22:00
The problem with these infections is that they cause a lot of damage. Even if we can clean the malware off your system, I cannot guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognize and logs won't show.
After cleaning the malware, you can still get errors afterwards because of the damage.
We can try to clean this up and do what we can, but keep in mind that we may not be able to solve ALL problems this malware already caused.
One of the problems is a password stealer:
C:\lich.exe
Info here: http://www.castlecops.com/o23list-3642.html
This allows hackers to steal critical system information and Download and Execute files.
I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
Though the Trojan has been identified and can be killed, because of its backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:
How to report ID theft, fraud, drive-by installs, hijacking and malware?
http://www.dslreports.com/faq/10451
When Should I Format, How Should I Reinstall
http://www.dslreports.com/faq/10063
I can help you in the cleaning if you don't want to reformat but I can't promise that we'll get you 100% clean.
Please let us know what you have decided to do in your next post.
areaF
59 Posts
0
December 21st, 2007 23:00
Bugbatter
3 Apprentice
•
20.5K Posts
0
December 22nd, 2007 01:00
That would be enough to scare me!
As far as the WIFI, there should be a way to disconnect. Typically, you would go to your WIFI icon by the clock. Rt-click "View Available Wireless Networks". When that window comes up, click the DISCONNECT button for the wireless network that the computer is on.
Considering the malware on there, I cannot guarantee that our fixes will go smoothly, so it would be good for your daughter to start backing up her important documents now.
If you decide to reformat, you can order your OS CD from Dell.
https://support.dell.com/support/topics/global.aspx/support/dellcare/en/backupcd_form
If you want to continue here and try to clean this, please remove any P2P (file sharing) programs before we begin.
areaF
59 Posts
0
December 22nd, 2007 23:00
Bugbatter
3 Apprentice
•
20.5K Posts
0
December 23rd, 2007 03:00
We'll just a do a little at a time and see how things go. You will need to download our tools from the internet. Therefore, it would be easiest to use that machine, but if you do not want to do that, you will need to download them to a USB stick or CD and transfer them to the infected machine.
I'll try to fix the password stealer first, so that can use the infected machine online.
I see the service for McAfee Security Center, but I do not see it in the running processes. What happened to the anti-virus on that computer?
Download SDFix and save it to the Desktop.
Do not run it yet.
Open a command prompt:
Click start >run > type cmd and hit Enter
Into the command window type the following commands one at a time, hit Enter AFTER EACH LINE
sc stop ZZZsvc_lich
sc delete ZZZsvc_lich
Delete this file:
C:\ lich.exe
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
Your HijackThis is outdated.
Please download HJT Installer for version 2.02 from Here to your desktop.
If not available use this alternate link: Here
When the log pops up in Notepad, copy and paste that file back here along with the log from SDFix.
areaF
59 Posts
0
December 23rd, 2007 07:00
SDFix: Version 1.119
Run by Progressive Invest on Sat 12/22/2007 at 10:23 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
kcp
noskrnl.sys
ZZZdrv_lich
Path:
kcp - Deleted
noskrnl.sys - Deleted
ZZZdrv_lich - Deleted
Infected Winlogon.exe Found!
Winlogon File Locations:
"C:\WINDOWS\system32\winlogon.exe" 502784 12/22/2007 06:08 AM
"C:\WINDOWS\system32\dllcache\winlogon.exe" 502784 12/22/2007 09:45 PM
Modified Files Are Listed Below:
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\dllcache\winlogon.exe
Note: SDFix Does Not Repair This File!
Infected ip6fw.sys Found!
ip6fw.sys File Locations:
"C:\WINDOWS\system32\drivers\ip6fw.sys" 29056 08/10/2004 05:00 AM
Infected File Listed Below:
C:\WINDOWS\system32\drivers\ip6fw.sys
Trojan File copied to Backups Folder
Attempting to replace ip6fw.sys with original version...
Unable To Replace Infected File!
Infected beep.sys Found!
beep.sys File Locations:
"C:\WINDOWS\system32\dllcache\beep.sys" 37888 12/21/2007 10:01 AM
"C:\WINDOWS\system32\drivers\beep.sys" 37888 12/21/2007 10:01 AM
Infected File Listed Below:
C:\WINDOWS\system32\dllcache\beep.sys
C:\WINDOWS\system32\drivers\beep.sys
Trojan File copied to Backups Folder
Attempting to replace beep.sys with original version...
Original beep.sys Restored
Infected beep.sys Found!
beep.sys File Locations:
"C:\WINDOWS\system32\dllcache\beep.sys" 37888 12/21/2007 10:01 AM
"C:\WINDOWS\system32\drivers\beep.sys" 37888 12/21/2007 10:01 AM
Infected File Listed Below:
C:\WINDOWS\system32\dllcache\beep.sys
C:\WINDOWS\system32\drivers\beep.sys
Trojan File copied to Backups Folder
Attempting to replace beep.sys with original version...
Original beep.sys Restored
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Service asc3550p - Deleted after Reboot
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\DRIVERS\FJY60.SYS - Deleted
C:\WINDOWS\SYSTEM32\DRIVERS\FYN64.SYS - Deleted
C:\WINDOWS\SYSTEM32\DRIVERS\HMA37.SYS - Deleted
C:\WINDOWS\SYSTEM32\DRIVERS\HWT66.SYS - Deleted
C:\WINDOWS\SYSTEM32\DRIVERS\PIF30.SYS - Deleted
C:\Documents and Settings\All Users\Documents\Settings\bot.dll - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\1A.tmp.exe - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\C.tmp.exe - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\1.dllb - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\5.dllb - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\6.dllb - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\7.dllb - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\v3xd1.g22me - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\v4xd3.ga2me - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\v4xd6.gam5e - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\v5xd2.g3ame - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\v5xd4.ga2me - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\v6xdt4.game - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\vx1dt1.game - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\vx1dt3.game - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\vx3dt2.game - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\ma11x1dd12111v.game - Deleted
C:\Documents and Settings\Progressive Invest\Local Settings\Temp\ma1x1dd1v.game - Deleted
C:\WINDOWS\system32\shift.exe.exe - Deleted
C:\Documents and Settings\Progressive Invest\Application Data\antivirus.exe - Deleted
C:\Documents and Settings\Progressive Invest\Application Data\Install.dat - Deleted
C:\Documents and Settings\Progressive Invest\Start Menu\Programs\Brave-Sentry\BraveSentry.lnk - Deleted
C:\Documents and Settings\Progressive Invest\Start Menu\Programs\Brave-Sentry\Uninstall.lnk - Deleted
C:\DOCUME~1\PROGRE~2\LOCALS~1\Temp\0wl.tmp - Deleted
C:\autorun.inf - Deleted
C:\WINDOWS\poolsv.exe - Deleted
C:\WINDOWS\system32\9_exception.nls - Deleted
C:\WINDOWS\system32\conf.dat - Deleted
C:\WINDOWS\system32\drivers\kcp.sys - Deleted
C:\WINDOWS\system32\kr_done1 - Deleted
C:\WINDOWS\system32\lich.dat - Deleted
C:\WINDOWS\system32\m1ax1d1213216143v.exe - Deleted
C:\WINDOWS\system32\mstscex.dll - Deleted
C:\WINDOWS\system32\n.ini - Deleted
C:\WINDOWS\system32\newmaxxsv234.exe - Deleted
C:\WINDOWS\system32\noskrnl.sys - Deleted
C:\WINDOWS\system32\oleauth32.dll - Deleted
C:\WINDOWS\system32\rozmchild.dll - Deleted
C:\WINDOWS\system32\runtime.exe - Deleted
C:\WINDOWS\system32\spoolsvv.exe - Deleted
C:\WINDOWS\system32\svcp.csv - Deleted
C:\WINDOWS\system32\vedxg4am1et2.exe - Deleted
C:\WINDOWS\system32\vedxg6ame4.exe - Deleted
C:\WINDOWS\system32\vedxga1me4t1.exe - Deleted
C:\WINDOWS\system32\vedxga3me2.exe - Deleted
C:\WINDOWS\system32\vedxga4me1.exe - Deleted
C:\WINDOWS\system32\vx.tll - Deleted
C:\WINDOWS\system32\winlogon.scr - Deleted
C:\WINDOWS\system32\winsub.xml - Deleted
C:\SDFix\backups_old1\1.dllb - Deleted
C:\SDFix\backups_old1\2.dllb - Deleted
C:\SDFix\backups_old1\5.dllb - Deleted
C:\SDFix\backups_old1\6.dllb - Deleted
C:\SDFix\backups_old1\7.dllb - Deleted
C:\SDFix\backups_old1\v3xd1.g22me - Deleted
C:\SDFix\backups_old1\v4xd3.ga2me - Deleted
C:\SDFix\backups_old1\v4xd6.gam5e - Deleted
C:\SDFix\backups_old1\v5xd2.g3ame - Deleted
C:\SDFix\backups_old1\v5xd4.ga2me - Deleted
C:\SDFix\backups_old1\v6xdt4.game - Deleted
C:\SDFix\backups_old1\vx1dt1.game - Deleted
C:\SDFix\backups_old1\vx1dt3.game - Deleted
C:\SDFix\backups_old1\vx3dt2.game - Deleted
C:\SDFix\backups_old1\ma11x1dd12111v.game - Deleted
C:\SDFix\backups_old1\ma1x1dd1v.game - Deleted
C:\WINDOWS\system32\2_exception.nls - Deleted
C:\WINDOWS\system32\drivers\asc3550p.sys - Deleted
Folder C:\Documents and Settings\Progressive Invest\Start Menu\Programs\Brave-Sentry - Removed
Folder C:\Documents and Settings\All Users\Documents\Settings - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 22:30:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Xfy38]
"Type"=dword:00000001
"Tag"=dword:00000002
"Group"="System Reserved\0Boot Bus Extender\0System Bus Extender\0SCSI miniport\0Port\0Primary Disk\0SCSI Class\0SCSI CDROM Class\0FSFilter Infrastructure\0FSFilter System\0FSFilter Bottom\0FSFilter Copy Protection\0FSFilter Security Enhancer\0FSFilter Open File\0FSFilter Physical Quota Management\0FSFilter Encryption\0FSFilter Compression\0FSFilter HSM\0FSFilter Cluster File System\0FSFilter System Recovery\0FSFilter Quota Management\0FSFilter Content Screener\0FSFilter Continuous Backup\0FSFilter Replication\0FSFilter Anti-Virus\0FSFilter Undelete\0FSFilter Activity Monitor\0FSFilter Top\0Filter\0Boot File System\0Base\0Pointer Port\0Keyboard Port\0Pointer Class\0Keyboard Class\0Video Init\0Video\0Video Save\0File System\0Event Log\0Streams Drivers\0NDIS Wrapper\0COM Infrastructure\0UIGroup\0LocalValidation\0PlugPlay\0PNP_TDI\0NDIS\0TDI\0wltrysvc\0NetBIOSGroup\0ShellSvcGroup\0SchedulerGroup\0SpoolerGroup\0AudioGroup\0SmartCardGroup\0NetworkProvider\0RemoteValidation\0NetDDEGroup\0Parallel arbitrator\0Extended Base\0PCI Configuration\0MS Transactions\0"
"ErrorControl"=dword:00000001
"Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Xfy38]
"Type"=dword:00000001
"Tag"=dword:00000002
"Group"="System Reserved\0Boot Bus Extender\0System Bus Extender\0SCSI miniport\0Port\0Primary Disk\0SCSI Class\0SCSI CDROM Class\0FSFilter Infrastructure\0FSFilter System\0FSFilter Bottom\0FSFilter Copy Protection\0FSFilter Security Enhancer\0FSFilter Open File\0FSFilter Physical Quota Management\0FSFilter Encryption\0FSFilter Compression\0FSFilter HSM\0FSFilter Cluster File System\0FSFilter System Recovery\0FSFilter Quota Management\0FSFilter Content Screener\0FSFilter Continuous Backup\0FSFilter Replication\0FSFilter Anti-Virus\0FSFilter Undelete\0FSFilter Activity Monitor\0FSFilter Top\0Filter\0Boot File System\0Base\0Pointer Port\0Keyboard Port\0Pointer Class\0Keyboard Class\0Video Init\0Video\0Video Save\0File System\0Event Log\0Streams Drivers\0NDIS Wrapper\0COM Infrastructure\0UIGroup\0LocalValidation\0PlugPlay\0PNP_TDI\0NDIS\0TDI\0wltrysvc\0NetBIOSGroup\0ShellSvcGroup\0SchedulerGroup\0SpoolerGroup\0AudioGroup\0SmartCardGroup\0NetworkProvider\0RemoteValidation\0NetDDEGroup\0Parallel arbitrator\0Extended Base\0PCI Configuration\0MS Transactions\0"
areaF
59 Posts
0
December 23rd, 2007 07:00
"Start"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations"=str(7):"\x6264\4\x7fa8\36\x148;\20\0\xe020|\x6020|\xa020|\xffc0\xffffsystem32\DRIVERS\USBSTOR.SYS\0\0\xfff8\xffff\x718;\xffe0\xffff\x6b76\a\32\0\x8c28?\1\0\1D\x6553\x7672\x6369e\xfff8\xffff\x1078;\xffd8\xffff\x6b76\17\32\0\x87a0?\a\0\1\0\x6544\x6570\x646e\x6e4f\x6553\x7672\x6369e\xffe8\xffffdrvmcdb\0\0\0\xffa0\xffff\x6b6e \xbcb4\xb428\xa21b\x1c5\0\0\xfc58:\0\0\0\0\xffff\xffff\xffff\xffff\5\0\xf2b8:\x218\0\xffff\xffff\0\0\0\0,\0\34\0\0\0\n\0\x6150\x6172\x656d\x6574\x7372\0\0\0\xffd0\xffff\x6b76\24\4\x8000\0\0\4\0\1\0\x6f43\x6e6e\x6365\x4d74\x6c75\x6974\x6c70\x5065\x726f\x7374\0\0\xffd0\xffff\x6b76\25\4\x8000d\0\4\0\1\0\x654b\x6279\x616f\x6472\x6144\x6174\x7551\x7565\x5365\x7a69e\0\xffd0\xffff\x6b76\26\34\0\xff50:\1\0\1\0\x654b\x6279\x616f\x6472\x6544\x6976\x6563\x6142\x6573\x614e\x656d\0\xffe0\xffffKeyboardClass\0\xffd0\xffff\x6b76\24\4\x8000\3\0\4\0\1\0\x614d\x6978\x756d\x506d\x726f\x7374\x6553\x7672\x6369\x6465\0\0\xffd0\xffff\x6b76\24\4\x8000\1\0\4\0\1\0\x6553\x646e\x754f\x7074\x7475\x6f54\x6c41\x506c\x726f\x7374\0\0\xffa8\xffff\x6b6e \x52ee_\x4514\x1c8\0\0\x6690\35\1\0\1\0\xf640:\x63d8\x8002\5\0\x8478\36\x218\0\xffff\xffff\20\0\0\0\30\0D\0\x8a\0\6\0\x6d6b\x7869\x7265\0\xffd8\xffff\x6b76\17T\0\xd9b8E\1\0\1\0\x6e45\x6d75\x7250\x706f\x6150\x6567\x33732\xffd8\xffff\x6b76\r\4\x8000\xa8be\0\4\0\0011\x6844\x7063\x6552\x7274\x5479\x6d69e7\xffe0\xffff\x6b76\5L\0\x3d60N\1\0\1\0\x4c43\x4953D\0\xfff0\xffff\3\0\0@\xd740@\xffd8\xffff\x6b76\n<\0\xad38?\1\0\1e\x6544\x6976\x6563\x6544\x6373\x7672\x6369e\xffc8\xffffRoot\MS_NDISWANIP\0000\0\0\0\0\xffc0\xffffRoot\MS_PPPOEMINIPORT\0000\0\0\0\0 \0LegacyDriver\0\0\xffa8\xffff\x6b6e \xd61a4\x6585\x1c6\0\0\xffd0:\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xf110:\x74f0\20\xffff\xffff\0\0\0\0\20\0\xa8\0\0\0\b\0\x6553\x7563\x6972\x7974\xffe0\xffff\x6b76\b\xa8\0\x1e0;\3\0\1\0\x6553\x7563\x6972\x7974\xff50\xffff\1\x8014\x90\0\x9c\0\24\0000\0\2\34\1\0\x8002\24\x1ff\17\x101\0\0\x100\0\0\2`\4\0\0\24\x1fd\2\x101\0\0\x500\22\0\0\30\x1ff\17\x201\0\0\x500 \0\x220\0\0\24\x18d\2\x101\0\0\x500\v\0\0\30\x1fd\2\x201\0\0\x500 \0\x223\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\0\0\xffa8\xffff\x6b6e \xd9ea\xe443\x4513\x1c8\0\0\x6690\35\0\0\1\0\xffff\xffff\x58a0\x8000\5\0\x7428\e\x218\0\xffff\xffff\b\0\0\0\30\0\n\0\x8b\0\6\0\x534b\x6365\x4444\0\xffd0\xffffRoot\MS_PSCHEDMP\0000\0\xffd8\xffff\x6b76\f\x114\0\x7d70=\1\0\1!\x7953\x626d\x6c6f\x6369\x694c\x6b6e\W\xffe0\xffff\x6b76\0034\0hD\1\0\1\0\x664dg\0\0\xffe0\xffff\x6b76\4\4\x8000\20\0\4\0\1E\x7954\x6570\x05f0F\xffd8\xffff\x6b76\16,\0\xfd00:\1\0\1\xcc20\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\x6696\xffa0\xffff\x6b6e \xd9ea\xe443\x4513\x1c8\0\0\x6690\35\6\0\1\0\x1f98;\x59b8\x8000\a\0\x2330"\x218\0\xffff\xffff&\0\0\0\30\0\x1da\0\x8c\0\f\0\x616c\x6d6e\x6e61\x6573\x7672\x7265\0\0\xffd8\xffff\x6b76\f\xd0\0\x5738=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffd0\xffffRoot\MS_PSCHEDMP\0002\0\xffd8\xffff\x6b76\f\xd0\0\x3020=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffe0\xffff\x6b76\0034\0\x86a8?\1\0\1\0\x664dg\0\0\xffe0\xffff\x6b76\a\n\0\xf9b0:\1\0\1=\x6553\x7672\x6369e\xffd8\xffff\x6b76\0162\0\x608;\1\0\1\23\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\23\xffe0\xffffLocalSystem\0\0M\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\0\x6f43\x666e\x6769\x6c46\x6761\x6c73\0\0\xffd8\xffff\x6b76\16,\0\x430;\1\0\1w\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\r\xfff8\xffff\x1780;\xffe0\xffff\x6b76\3J\0\x9540L\1\0\1\0\x664dg\0\0\xffd8\xffff\x6b76\vb\0\x4c20E\1\0\1n\x6944\x7073\x616c\x4e79\x6d61efP\xffd8\xffff\x6b76\f\xd6\0\x3208=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xfff8\xffff\x2120;\xfff8\xffff\x1e30;\xffe0\xffff\0\0\0\0\0\0\1\0\xade0\b\1\0\x3e8\0\xffc8\xffffRoot\MS_PTIMINIPORT\0000\0\0\xfff8\xffff\x1988;\xffd8\xffff\x6b76\17\4\x8000\0\0\4\0\1:\x6844\x7063\x6552\x7274\x5379\x6174\x7574s\xffc8\xffff\x6b76\e\xe8b2\0\xfd90:\a\0\1\37\x6550\x646e\x6e69\x4667\x6c69\x5265\x6e65\x6d61\x4f65\x6570\x6172\x6974\x6e6fsMA\b\0x;\xffe8\xffffdisk.inf\0&\xffb0\xffff\x9180\0\x4338\0\xe4b8\1\xe670\1\xe0b0\16\xe230\16\x9390\25\xd8f0\26\x9348\25\xd710\26\xd6b8\26\xd768\26\xd738\26\xd7d8\26\xd850\26\xd7a0\26\xd810\26\x8258(\x03401\xffd8\xffff\x6b76\f\xc0\0\x3418=\1\0\1F\x7953\x626d\x6c6f\x6369\x694c\x6b6eDE\xfff8\xffff\x1d48;\xffd8\xffff\x6b76\16\4\x8000\a\0\4\0\1C\x7954\x6570\x5373\x7075\x6f70\x7472\x6465t\xfff0\xffff\x80f\xf09\x908\xf00\b\x293d\xffe0\xffff\x6b76\5\x28e\0\x6308K\a\0\1\0\x6f52\x7475eu\xfff8\xffff\x17a8;\xff98\xffff\x6b6e \x16b4\xb509\xa280\x1c5\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\0\0\xffff\xffff\x218\0\xffff\xffff\0\0\0\0\0\0\0\0\0\0\23\0\x7541\x6f74\x7574\x656e\x5064\x7261\x6d61\x7465\x7265s\0\0\xffa0\xffff\x6b6e \xae24\x1883\x6992\x1c6\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\17\0\xb50;\x218\0\xffff\xffff\0\0\0\0H\0\xbc\0\1\0\17\0\x6544\x6166\x6c75\x5374\x6365\x7275\x7469y\xff58\xffff\1\x8004\x8c\0\x98\0\0\0\24\0\2x\5\0\0\30\3\17\x201\0\0\x500 \0\x220\0\0\30\3\17\x201\0\0\x500 \0\x225\0\0\30\3\17\x201\0\0\x500 \0\x227\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xffd0\xffff\x6b76\27|\0\x948;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x4165\x6d64\x6e69\x6f43\x6e6e\x6365t\xff80\xffff\1\x8004d\0p\0\0\0\24\0\2P\3\0\0\30\3\17\x201\0\0\x500 \0\x220\0\0\30\3\17\x201\0\0\x500 \0\x225\0\0\30\3\17\x201\0\0\x500 \0\x227\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xffd0\xffff\x6b76\21\x90\0\x71f0F\3\0\1\2\x7253\x7376\x6376\x6553\x7373\x6f69\x496e\x666e\x16f\2\x201\0\xffd0\xffff\x6b76\24x\0\xa28;\3\0\1\0\x7253\x7376\x6376\x7453\x7461\x7369\x6974\x7363\x6e49\x6f66\0\0\xff80\xffff\1\x8004`\0l\0\0\0\24\0\2L\3\0\0\30\1\17\x201\0\0\x500 \0\x220\0\0\30\1\17\x201\0\0\x500 \0\x225\0\0\24\1\0\x101\0\0\x200\0\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\0\0\xffc8\xffff\x6b76\34\4\x8000\1\0\4\0\1\0\x6e41\x6e6f\x6d79\x756f\x4473\x7365\x7263\x7069\x6f74\x7372\x7055\x7267\x6461\x6465\0\0\xffd8\xffff\x6b76\16"\0\x1e58;\1\0\0013\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\0\xfff0\xffff\xf44\x96\0\x12c\x1f40\0\xffc8\xffff\x6b76\34\4\x8000\0\0\4\0\1\0\x7250\x7665\x6f69\x7375\x6e41\x6e6f\x6d79\x756f\x5273\x7365\x7274\x6369\x6974\x6e6f\0\0\xffc0\xffff\x12b0;\xc70;\xca0;\xcc8;\xcf8;\xf40;\x1018;\x1048;\x10a0;\x918;\x9f8;\xaa8;\xb18;\x9c8;\x89c8F\xfff8\xffff\xae0;\xffe8\xffff\x686c\2\x0908F\xea98\x6e7f\x09b0F\xe2d0\xe465\xff40\xffff\1\x8004\xa0\0\xac\0\0\0\24\0\2\x8c\6\0\0\30\27\17\x201\0\0\x500 \0\x220\0\0\30\27\17\x201\0\0\x500 \0\x225\0\0\24\27\17\x101\0\0\x500\22\0\0\30\3\0\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\0\0\xffd0\xffff\x6b76\23\xa4\0\xd50;\3\0\1\0\x7253\x7376\x6376\x7254\x6e61\x7073\x726f\x4574\x756em\0\0\xffd8\xffff\x6b76\20\x94\0\xdf8;\3\0\1\0\x7253\x7376\x6376\x6f43\x6e6e\x6365\x6974\x6e6f\xffd0\xffff\x6b76\24d\0\xe90;\3\0\1\0\x7253\x7376\x6376\x6553\x7672\x7265\x6944\x6b73\x6e45\x6d75\0\0\xffd8\xffff\x6b76\n|\0\x12d8;\3\0\1\0\x7253\x7376\x6376\x6946\x656c\0\0\0\xffe0\xffff\x6b76\6\x432\0\xd900L\a\0\1\0\x7845\x6f70\x7472i\xfff0\xffff\4\0\0@\xc208@\xff58\xffff\1\x8004\x8c\0\x98\0\0\0\24\0\2x\5\0\0\30\27\17\x201\0\0\x500 \0\x220\0\0\30\27\17\x201\0\0\x500 \0\x225\0\0\24\27\17\x101\0\0\x500\22\0\0\30\3\0\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x500\v\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xff68\xffff\1\x8004|\0\x88\0\0\0\24\0\2h\4\0\0\30\1\17\x201\0\0\x500 \0\x220\0\0\30\1\17\x201\0\0\x500 \0\x225\0\0\30\1\0\x201\0\0\x500 \0\x226\0\0\30\1\0\x201\0\0\x500 \0\x223\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xff98\xffff\1\x8004L\0X\0\0\0\24\0\28\2\0\0\30\1\17\x201\0\0\x500 \0\x220\0\0\30\1\17\x201\0\0\x500 \0\x225\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xffd8\xffff\x6b76\16"\0\x1758;\1\0\1t\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563o\xffe0\xffff192.168.1.1\0\0\0\xffd0\xffff\x6b76\23\xa4\0\xf70;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x4665\x6c69\x4965\x666eo\0\0\xff58\xffff\1\x8004\x8c\0\x98\0\0\0\24\0\2x\5\0\0\30\23\17\x201\0\0\x500 \0\x220\0\0\30\23\17\x201\0\0\x500 \0\x225\0\0\30\23\17\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xffd0\xffff\x6b76\24\xbc\0\x1110;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x5065\x6972\x746e\x6e49\x6f66\0\0\xffd0\xffff\x6b76\24\xa4\0\x11d0;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x4165\x6d64\x6e69\x6e49\x6f66\0\0\xffd8\xffff\x6b76\f\xd8\0\x3718=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffd0\xffff\x6b76\22\xa4\0\x870;\3\0\1\0\x7253\x7376\x6376\x6853\x7261\x4365\x6e6f\x656e\x7463\0\0\0 \0\xe4f8:\xe9b8:\x858=\xfd90:\xb850C\xe558C\xe800C\xffe0\xffff\x6b76\4\x362\0\x13c0;\a\0\1a\x6942\x646eis\xff40\xffff\1\x8004\xa4\0\xb0\0\0\0\24\0\2\x90\6\0\0\30\23\17\x201\0\0\x500 \0\x220\0\0\30\23\17\x201\0\0\x500 \0\x225\0\0\30\23\17\x201\0\0\x500 \0\x226\0\0\30\23\17\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xff58\xffff\1\x8004\x8c\0\x98\0\0\0\24\0\2x\5\0\0\30\23\17\x201\0\0\x500 \0\x220\0\0\30\2\0\x201\0\0\x500 \0\x225\0\0\30\2\0\x201\0\0\x500 \0\x223\0\0\24\1\0\x101\0\0\x100\0\0\0\24\1\0\x101\0\0\x500\a\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xfff8\xffff\x1d70;\xffd0\xffff\x6b76\27\4\x8000\1\0\4\0\1\0\x6e65\x6261\x656c\x6573\x7563\x6972\x7974\x6973\x6e67\x7461\x7275e\xffd8\xffff\x6b76\20\xb8\0\xbb0;\3\0\1\0\x7253\x7376\x6376\x6f43\x666e\x6769\x6e49\x6f66\xff80\xffff\1\x8004d\0p\0\0\0\24\0\2P\3\0\0\30\21\17\x201\0\0\x500 \0\x220\0\0\30\21\17\x201\0\0\x500 \0\x225\0\0\30\21\17\x201\0\0\x500 \0\x223\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\xfff0\xffff011@\xc7a0@\xffa8\xffff\x6b6e \x242eX\xcd60\x1c6\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\3\0\xee78\32\x218\0\xffff\xffff\0\0\0\0\f\0\x432\0\2\0\a\0\x694c\x6b6e\x6761e\xfc98\xffff\Device\NetbiosSmb\0\Device\NetBT_Tcpip_{A63D250C-D9FF-4DF6-8DC1-C8F98F2E7539}\0\Device\NetBT_Tcpip_{B6D36F25-35E9-491D-91AF-34E4B0954885}\0\Device\NetBT_Tcpip_{683D9BA7-E222-4B49-8C13-B1D8F48C39E7}\0\Device\NetBT_Tcpip_{B1A579A3-BC60-43D9-BB6C-798D05FA638C}\0\Device\NetBT_Tcpip_{61E68846-AE27-44B7-B0FB-0C629F393B8A}\0\Device\NetBT_Tcpip_{29B39846-0902-49E5-B96A-2F1FC54E9A72}\0\Device\NetBT_Tcpip_{2F9FBC39-C724-4E7B-AEFD-EDFE1FAC9BF8}\0\0t\xffd0\xffff\x6b76\21\4\x8000\x5113\x476c\4\0\1E\x654c\x7361\x4f65\x7462\x6961\x656e\x5464\x6d69\x7f65E\xae00E\xffd8\xffffRoot\SYSTEM\0000\0\0\xffd8\xffff\x6b76\16"\0\x17d0;\1\0\1\0\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\0\xffd8\xffff\x6b76\16f\0\x38a8=\1\0\1s\x6544\x6976\x6563\x6e49\x7473\x6e61\x65638\xffd8\xffffRoot\SYSTEM\0000\0q\xffd0\xffff\x5288:\x8de0:\x7580:\x9828:\x8ae8:\x8f68:\x98e0:\xa7e0:\x52a8:\xe460:\xe2c0:\xffe0\xffff\x6b76\b\b\0\xbaa0\35\3\0\1\0\x3031\x4232\x3530\x3032\xffe0\xffff\x6b76\6\4\x8000\1\0\4\0\1.\x654c\x6167\x7963\0\xffd8\xffff\x6b76\n\16\0\x4f68\37\1\0\1\0\x6544\x6976\x6563\x6544\x6373\x4e50F\0\xffc0\xffffsystem32\DRIVERS\ipnat.sys\0\0\0\0\xffd8\xffff\x6b76\f\xd8\0\x5130=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffe0\xffff\xed80"\xe3c0:\xed70:\x1b88;\xf338:\xa8;\L\xffe8\xffffMicrosoft\0\xffa8\xffff\x6b6e \xf110\xe4d9\x43e1\x1c8\0\0\x5748\20\1\0\0\0\xf2a0:\xffff\xffff\n\0\x3cd0D\x218\0\xffff\xffff\20\0\0\0\36\0n\0\\0\a\0\x6865\x6552\x7663\x4d72\xffd8\xffff\x6b76\f\x114\0\x65f0=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\xff48+\xffd8\xffff\xcc68\32\xcd58\32\xcc28\32\xcdb8\32\xc580\32\xce38\32\x7418"\x7ac8"\x3bc0!\xfff0\xffff\x2ee\x02eed\5\xc746@\xffe0\xffff\x6b76\2\4\x8000\x9003\x44f7\4\0\1\0\x3154\0\x21d4&\xffd8\xffff\x6b76\v<\0\x1210D\1\0\1r\x6944\x7073\x616c\x4e79\x6d61\x6565on\xffe0\xffff\x6b76\5\4\x8000\3\0\4\0\1c\x7453\x7261\x6b74\4\xffd8\xffff\x6b76\n\30\0\x1a78;\1\0\1\0\x6544\x6976\x6563\x6544\x6373e\0\0\xffe0\xffffZZZdrv_lich\0te\xffd8\xffff\x6b76\v<\0\xe580C\1\0\1:\x6944\x7073\x616c\x4e79\x6d61e\x1728;\xffc0\xffff\x6b76!\4\x8000\xffff\xffff\4\0\1g\x7355\x7265\x614d\x7473\x7265\x6544\x6976\x6563\x6954\x696d\x676e\x6f4d\x6564\x6c41\x6f6c\x6577d\WI\xfff8\xffff\x318;\xffa0\xffff\x6b6e \x3258\xfacb\x4513\x1c8\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\f\0\x46e0M\x218\0\xffff\xffff\0\0\0\0000\0\x90\0\3\0\n\0\x6170\x6172\x656d\x6574\x7372\0\0\0\xffe0\xffff\x6b76\5\32\0\xfdd0<\1\0\1v\x6c43\x7361\x7973e\xffe0\xffff\x6b76\5\32\0\xf278:\1\0\1E\x6c43\x7361\x6973\x7974\xffc8\xffffCOM+ System Application\0di\xffa8\xffff\x6b6e \xf20\xa0fe\xc11f\x1c7\0\0\x5748\20\1\0\0\0\xfae8:\xffff\xffff\6\0\x5f50D\x218\0\xffff\xffff\20\0\0\0\30\0\x82\0\x15b\0\6\0\x7557\x6664\x6452t\xffc0\xffffsystem32\DRIVERS\wudfrd.sys\0ca\xffd8\xffff\x6b76\v\x82\0\x1ca0;\1\0\1n\x6944\x7073\x616c\x4e79\x6d61e\x6b76\16\xff78\xffffWindows Driver Foundation - User-mode Driver Framework Reflector\0\t\xffe0\xffff\x6b76\b\xa8\0\x5e08D\3\0\1\x7461\x6553\x7563\x6972\x7974\xffd8\xffff\x6b76\16\x9a\0\x4940=\1\0\1\0\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563\0\xffd8\xffff\x6b76\f\xfa\0\x6b20=\1\0\1\0\x7953\x626d\x6c6f\x6369\x694c\x6b6e\0\0\xffe0\xffff\xa408\36\x5308\37\x5688\37\x5548\37\x1eb8 \x9e100\0\0\xffd8\xffff\x6b76\r\2\x8000\0\0\a\0\1M\x6544\x6570\x646e\x6e4f\x7247\x756f\x6370e\b\0\x670;\xffe0\xffff\x6b76\b\xa8\0\x1ee8;\3\0\1\0\x6553\x7563\x6972\x7974\xffd8\xffff\x6b76\n\30\0\xfe40\34\1\0\1o\x624f\x656a\x7463\x614e\x656d\0Mi\xffd8\xffff\x6b76\f\x100\0\x77a0=\1\0\0016\x7953\x626d\x6c6f\x6369\x694c\x6b6e\x92c0<\xffd8\xffffRoot\SYSTEM\0000\0002\xfff0\xffff011@\xcac8@\xffa8\xffff\x6b6e \x6dba\x93cc\xa281\x1c5\0\0\x3a8;\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xf5a8:\x74f0\20\xffff\xffff\0\0\0\0\20\0\xa8\0\4\0\b\0\x6553\x7563\x6972\x7974\xff50\xffff\1\x8014\x90\0\x9c\0\24\0000\0\2\34\1\0\x8002\24\x1ff\17\x101\0\0\x100\0\0\2`\4\0\0\24\x18d\2\x101\0\0\x500\v\0\0\30\x19d\2\x201\0\0\x500 \0\x223\0\0\30\x1ff\17\x201\0\0\x500 \0\x220\0\0\24\x1fd\2\x101\0\0\x500\22\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0\0\0\xffc0\xffff\x686c\6\x7a8;\xfb41\xc485\x810;\x55dd\x240d\x1368;\x59b7\x9d4a\x1b08;\xea98\x6e7f\x1e90;\xe2d0\xe465\xe020:\xb4c2\x5f4d\x1e50;#\0\xffd8\xffff\x6b76\nB\0PF\2\0\1e\x6553\x7672\x6369\x4465\x6c6cM\0d\x6268\x6e69\x2000;\x1000\0\0\0\0\0\0\0\0\0\0\0\xffc0\xffffsystem32\DRIVERS\ipsec.sys\0til\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\0\x6f43\x666e\x6769\x6c46\x6761s\0\0\xffc8\xffff\x6b76\34\30\0\xedc0\35\1\0\1>\x6f43\x6f6c\x7275\x7546\x6c6c\x6373\x6572\x6e65\x6f43\x746e\x6172\x7473\x445f\x4645\x56c8>\xffd8\xffff\x6b76\v\32\0\x5098\37\1\0\1o\x6944\x7073\x616c\x4e79\x6d61ee \xffc8\xffffRoot\MS_L2TPMINIPORT\0000\0\xffd8\xffff\x6b76\16\x9a\0\x5970=\1\0\0010\x6544\x6976\x6563\x6e49\x7473\x6e61\x6563<\xffd8\xffff\x6b76\n`\0\x39a0D\1\0\1\0\x6544\x6976\x6563\x6544\x6373\0\0\0\b\0\xa398!\xffd8\xffff\x6b76\v\4\x8000\0\0\4\0\1\a\x6f43\x666e\x6769\x6c46\x6761s\0017\xffc8\xffffFSFilter Infrastructure\0\0\0\xfff0\xffff\17\xf0b\xb00\xf00\b\x4b5f\xffd8\xffff\x6b76\tN\0\x4548E\1\0\1\0\x6c43\x7361\x4773\x4955D\0\0\0\xffa8\xffff{4D36E97D-E325-11CE-BFC1-08002BE10318}\0\x7478\x6e49\x7473\xffa0\xffff\x6b6e \xba9a\x5641\xa281\x1c5\0\0\x7bd0F\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2350;\x218\0\xffff\xffff\0\0\0\0\24\0\\0\0\0\n\0\x6150\x6172\x656d\x6574\x7372are\xffd8\xffff\x6b76\n\\0\x22f0;\2\0\1\26\x6553\x7672\x6369\x4465\x6c6c\26\x7e00\26\xffa0\xffff%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll\0\xfff8\xffff\x22c8;\xffa8\xffff\x6b6e \xd322\x55d8\xa281\x1c5\0\0\x7bd0F\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2480;\x74f0\20\xffff\xffff\0\0\0\0\20\0\xa8\0\1\0\b\0\x6553\x7563\x6972\x7974\xffe0\xffff\x6b76\b\xa8\0\x23d0;\3\0\1a\x6553\x7563\x6972\x7974\xff50\xffff\1\x8014\x90\0\x9c\0\24\0000\0\2\34\1\0\x8002\24\x1ff\17\x101\0\0\x100\0\0\2`\4\0\0\24\x1fd\2\x101\0\0\x500\22\0\0\30\x1ff\17\x201\0\0\x500 \0\x220\0\0\24\x18d\2\x101\0\0\x500\v\0\0\30\x1fd\2\x201\0\0\x500 \0\x223\0\x101\0\0\x500\22\0\x101\0\0\x500\22\0Sy\xfff8\xffff\x23b0;\xffe8\xffff\x686c\2\x2268;\xea98\x6e7f\x2358;\xe2d0\xe465\xffa8\xffff\x6b6e \x5a5a\xb426\xa21b\x1c5\0\0\x6690\35\1\0\0\0\x2858;\xffff\xffff\b\0\x2a40;\x218\0\xffff\xffff\24\0\0\0\36\0\x2e6\0o\0\a\0\x6948\x5364\x7265v\xffd8\xffff\x6b76\17\16\0\x2520;\a\0\1\0\x6544\x6570\x646e\x6e4f\x6553\x7672\x6369e\xffe8\xffffRpcSs\0\0\0\0\0\xfff8\xffff\x2ac8;\xffd8\xffff\x6b76\v\x2e6\0\x2568;\1\0\1\0\x6544\x6373\x6972\x7470\x6f69n\0\0\xfd10\xffffEnables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.\0\0\0\0\xfff0\xffff\x686c\1\x2a68;\xea98\x6e7f\xffd8\xffff\x6b76\v<\0\x2890;\1\0\1\0\x6944\x7073\x616c\x4e79\x6d61e\0\0\xffc0\xffffHuman Interface Device Access\0\xffd8\xffff\x6b76\f\4\x8000\1\0\4\0\1\0\x7245\x6f72\x4372\x6e6f\x7274\x6c6f\0\0\xfff0\xffffhpn\0\x5518.\xfff8\xffff\x2d70;\xffd8\xffff\x6b76\tZ\0\x2938;\2\0\1\0\x6d49\x6761\x5065\x7461h\0\0\0\xffa0\xffff%SystemRoot%\System32\svchost.exe -k netsvcs\0\0\xffd8\xffff\x6b76\n\30\0\x29c0;\1\0\1\0\x624f\x656a\x7463\x614e\x656d\0\0\0\xffe0\xffffLocalSystem\0\0\0\xffe0\xffff\x6b76\5\34\0\x2bb8;\1\0\1\0\x7247\x756fp\0\xffe0\xffff\x6b76\5\4\x8000\4\0\4\0\1\0\x7453\x7261t\0\xffe0\xffff\x6b76\4\4\x8000 \0\4\0\1\0\x7954\x6570\0\0\xffd8\xffff\x24f8;\x2540;\x2868;\x28d0;\x2910;\x2998;\x2a00;\x2a20;\0\0\xffa0\xffff\x6b6e \x5a5a\xb426\xa21b\x1c5\0\0\x24a0;\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2538;\x218\0\xffff\xffff\0\0\0\0\24\0D\0\0\0\n\0\x6150\x6172\x656d\x6574\x7372\0\0\0\xffd8\xffff\x6
areaF
59 Posts
0
December 23rd, 2007 07:00
areaF
59 Posts
0
December 23rd, 2007 07:00
areaF
59 Posts
0
December 23rd, 2007 07:00
Scan saved at 10:44:32 PM, on 12/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Broadcom\BACS\BacsTray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\shovth.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: Ted Nugent Toolbar - {4E7BD74F-2B8D-469E-BDDE-CF39F0D3F960} - C:\PROGRA~1\PRODEG~1\PRODEG~1.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Ted Nugent Toolbar - {4E7BD74F-2B8D-469E-BDDE-CF39F0D3F960} - C:\PROGRA~1\PRODEG~1\PRODEG~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ShowLOMControl]
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [bacstray] C:\Program Files\Broadcom\BACS\BacsTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [poolsv] "C:\WINDOWS\poolsv.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Medichi2] medichi2.exe
O4 - HKLM\..\Run: [Medichi] medichi.exe
O4 - HKLM\..\Run: [sis32] C:\WINDOWS\system32\winsos.exe
O4 - HKLM\..\Run: [winroot] C:\WINDOWS\system32\winsn.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.clarkcolor.com/ClarkActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
End of file - 9282 bytes
areaF
59 Posts
0
December 23rd, 2007 08:00
areaF
59 Posts
0
December 23rd, 2007 08:00
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\de.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\es.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\fr.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\help.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\it.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\ja.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ko\ko.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\dell\High Speed Internet Offers\Consumer\media\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Documents and Settings\Progressive Invest\Desktop\hijackthis.exe\backups\backups.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\i386\SP1\Windows\System32\Drivers\Drivers.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\i386\SP2\Windows\System32\Drivers\Drivers.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\ActiveX.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\plug_ins.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Acrobat 6.0\Resource\CMap\CMap.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Acrobat 6.0\Resource\Font\Font.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\Font.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\AIR\AIR.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\AMT\AMT.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\Browser\Browser.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\Javascripts\Javascripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\Optional\Optional.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\plug_ins.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins3d\plug_ins3d.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\SPPlugins\SPPlugins.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\Tracker\Tracker.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Resource\CMap\CMap.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Resource\Font\Font.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Setup Files\{AC76BA86-7AD7-1033-7B44-A81000000003}\{AC76BA86-7AD7-1033-7B44-A81000000003}.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\America Online 9.0\media\nmpx\plugins\plugins.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\America Online 9.0\media\nmpxchat\plugins\plugins.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\America Online 9.0\vim\resources\audioprogress\audioprogress.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\America Online 9.0\vim\resources\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\America Online 9.0\vim\resources\videoprogress\videoprogress.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\AOL Companion\UI\Default\modules\modules.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\Help.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Welcome\Welcome.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\Help.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Welcome\Welcome.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\Help.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Welcome\Welcome.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhelp.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\Help.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\Help.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Welcome\Welcome.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\dell\High Speed Internet Offers\Consumer\media\images\buttons\buttons.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\dell\High Speed Internet Offers\Consumer\media\images\promos\promos.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\dell\High Speed Internet Offers\Consumer\media\images\titles\titles.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Annotations\Annotations.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig709\ENU_\ENU_.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Adobe Help Viewer\1.0\Resources\en\en.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\adobe_epic\eula\eula.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\HowTo\ENU\ENU.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\IDTemplates\ENU\ENU.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\Legal\en_US\en_US.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\AcroForm\AcroForm.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\ImageViewer\ImageViewer.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\VDKHome\VDKHome.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins3d\prc\prc.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Resource\Font\PFM\PFM.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Resource\Linguistics\LanguageNames\LanguageNames.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhelp.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Welcome\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhelp.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Welcome\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhelp.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Welcome\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhdata\common\common.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhdata\js\js.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\wwhimpl.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhelp.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhelp.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Welcome\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\adobe_epic\eula\en_US\en_US.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\BeyondReader\ENU\Onramp\Onramp.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\HowTo\ENU\Images\Images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\AcroForm\PMP\PMP.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\Annotations\Stamps\Stamps.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\ImageViewer\en_US\en_US.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\Multimedia\MPP\MPP.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\VDKHome\ENU\ENU.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Resource\Linguistics\Providers\Proximity\Proximity.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhdata\common\common.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhdata\js\js.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\wwhimpl.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhdata\common\common.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhdata\js\js.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\wwhimpl.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhdata\common\common.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhdata\js\js.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\wwhimpl.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhdata\js\search\search.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhdata\common\common.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhdata\js\js.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\wwhimpl.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhdata\common\common.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhdata\js\js.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\wwhimpl.exe"
Fri 22 Jun 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
areaF
59 Posts
0
December 23rd, 2007 08:00
Sun 15 Apr 2007 8 A..H. --- "C:\Documents and Settings\Progressive Invest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun 15 Apr 2007 8 A..H. --- "C:\Documents and Settings\Progressive Invest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sun 22 Apr 2007 8 A..H. --- "C:\Documents and Settings\Progressive Invest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\Annotations\Stamps\ENU\ENU.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhdata\js\search\search.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhdata\js\search\search.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhdata\js\search\search.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\common\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\common\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\common\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\common\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\java\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\java\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\java\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\js\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\js\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\js\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\help\wwhelp\wwhimpl\js\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhdata\js\search\search.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhdata\js\search\search.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\common\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\common\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\common\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\common\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\java\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\java\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\java\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\js\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\js\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\js\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\de\Help\wwhelp\wwhimpl\js\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\common\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\common\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\common\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\common\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\java\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\java\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\java\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\js\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\js\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\js\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\es\Help\wwhelp\wwhimpl\js\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\common\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\common\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\common\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\common\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\java\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\java\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\java\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\js\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\js\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\js\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\fr\Help\wwhelp\wwhimpl\js\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\common\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\common\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\common\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\common\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\java\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\java\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\java\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\js\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\js\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\js\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\it\Help\wwhelp\wwhimpl\js\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\common\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\common\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\common\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\common\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\java\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\java\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\java\scripts\scripts.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\js\html\html.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\js\images\images.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\js\private\private.exe"
Thu 20 Dec 2007 89,088 ...H. --- "C:\Program Files\ATI Technologies\ATI.ACE\ja\Help\wwhelp\wwhimpl\js\scripts\scripts.exe"
Hope I got it all.....power went out half way through.
areaF
59 Posts
0
December 23rd, 2007 08:00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Xfy38]
"Type"=dword:00000001
"Tag"=dword:00000002
"Group"="System Reserved\0Boot Bus Extender\0System Bus Extender\0SCSI miniport\0Port\0Primary Disk\0SCSI Class\0SCSI CDROM Class\0FSFilter Infrastructure\0FSFilter System\0FSFilter Bottom\0FSFilter Copy Protection\0FSFilter Security Enhancer\0FSFilter Open File\0FSFilter Physical Quota Management\0FSFilter Encryption\0FSFilter Compression\0FSFilter HSM\0FSFilter Cluster File System\0FSFilter System Recovery\0FSFilter Quota Management\0FSFilter Content Screener\0FSFilter Continuous Backup\0FSFilter Replication\0FSFilter Anti-Virus\0FSFilter Undelete\0FSFilter Activity Monitor\0FSFilter Top\0Filter\0Boot File System\0Base\0Pointer Port\0Keyboard Port\0Pointer Class\0Keyboard Class\0Video Init\0Video\0Video Save\0File System\0Event Log\0Streams Drivers\0NDIS Wrapper\0COM Infrastructure\0UIGroup\0LocalValidation\0PlugPlay\0PNP_TDI\0NDIS\0TDI\0wltrysvc\0NetBIOSGroup\0ShellSvcGroup\0SchedulerGroup\0SpoolerGroup\0AudioGroup\0SmartCardGroup\0NetworkProvider\0RemoteValidation\0NetDDEGroup\0Parallel arbitrator\0Extended Base\0PCI Configuration\0MS Transactions\0"
"ErrorControl"=dword:00000001
"Start"=dword:00000000
areaF
59 Posts
0
December 23rd, 2007 08:00