Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Help, getting these annoying lines on my Monitor! [Solved]


  • This topic is locked This topic is locked

#1
Jason1230

Jason1230

    New Member

  • Member
  • Pip
  • 8 posts
Hiya, this is my first hijack log so please be nice :)

I recently downloaded a program which I think contained a virus in it, the problem started happening when I restarted my computer after installing the program. I get these black lines on my monitor all the time, but everything else seems to be working fine i.e. the computer is not slowing down, no pop-ups etc.

I've tried running scans with SuperAntiSpyware Free Edition, and Avast! Pro Edition, but nothing comes up. I've even done a reinstallation of my system but it keeps coming back!! :)

My current security programs include SuperAntiSpyware Free Edition, and Avast! Pro Edition, Spyware Blaster, Ad-Aware 2008 and CCleaner (if that counts).



Here's a screenie of my desktop showing these lines:

Posted Image



Is this a virus infected problem? Or has this got to do with my video cards? Though I think its more due to a virus than a hardware problem. Can someone help me with my problem?? Thanks alot in advance.


HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:59:02, on 31/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Styler\Styler.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/?p=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Styler.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 6149 bytes
  • 0

Advertisements


#2
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Hello Jason1230

welcome to geekstogo :) and sorry to keep you waiting.

can you ever get rid of the lines, or are they always there?


====STEP 1====
lets put you into safe mode and see if the lines are still there:

once in safe mode, see what it looks like, then reboot your machine and go onto Step2.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
====STEP 2====
  • Download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts.


andrewuk
  • 0

#3
Jason1230

Jason1230

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
I cannot ever get rid of these lines when in normal mode, but they don't seem to appear when I boot in Safe Mode.

Here are the logs

log.txt:

Logfile of random's system information tool 1.05 (written by random/random)
Run by Jason at 2009-02-07 23:53:58
Microsoft Windows XP Professional Service Pack 3
System drive C: has 92 GB (80%) free of 114 GB
Total RAM: 511 MB (20% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:54:07, on 07/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Styler\Styler.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Jason\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Jason.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/?p=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Styler.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 6293 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-17 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-17 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-17 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - StylerToolBar - C:\Program Files\Styler\TB\StylerTB.dll [2006-05-02 102400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LClock"=C:\Program Files\LClock\LClock.exe [2004-09-19 65536]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2006-09-07 15872]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-17 136600]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2007-12-04 79224]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"CTHelper"=C:\WINDOWS\CTHELPER.EXE [2006-08-11 17920]
"CTxfiHlp"=C:\WINDOWS\system32\CTXFIHLP.EXE [2006-08-11 18944]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-03-22 1271808]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-01-24 1830128]

C:\Documents and Settings\Jason\Start Menu\Programs\Startup
Styler.lnk - C:\Documents and Settings\Jason\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-06-19 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2009-02-07 23:53:58 ----D---- C:\rsit
2009-02-07 11:40:50 ----A---- C:\WINDOWS\ntbtlog.txt
2009-02-02 22:18:49 ----D---- C:\Program Files\Guild Wars
2009-01-31 13:58:20 ----D---- C:\Program Files\Trend Micro
2009-01-25 20:33:42 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-01-25 20:32:54 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-01-25 20:32:18 ----D---- C:\Program Files\Common Files\Adobe
2009-01-25 20:32:18 ----D---- C:\Program Files\Adobe
2009-01-25 20:24:20 ----D---- C:\Program Files\NOS
2009-01-25 20:24:20 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-01-18 11:32:20 ----D---- C:\WINDOWS\Sun
2009-01-18 01:08:16 ----A---- C:\WINDOWS\{00000002-00000000-00000000-00001102-00000004-10031102}.BAK
2009-01-18 01:04:15 ----D---- C:\WINDOWS\system32\Defaults
2009-01-18 01:03:19 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2009-01-18 01:03:19 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2009-01-18 01:03:14 ----D---- C:\Documents and Settings\Jason\Application Data\Creative
2009-01-18 01:02:53 ----D---- C:\WINDOWS\system32\Data
2009-01-18 01:02:53 ----A---- C:\WINDOWS\system32\instwdm.ini
2009-01-18 01:02:53 ----A---- C:\WINDOWS\system32\ctzapxx.ini
2009-01-18 01:02:53 ----A---- C:\WINDOWS\INRES.DLL
2009-01-18 01:02:53 ----A---- C:\WINDOWS\CTXFIRES.DLL
2009-01-18 01:02:53 ----A---- C:\WINDOWS\CTDCRES.DLL
2009-01-18 01:02:52 ----D---- C:\Program Files\Creative
2009-01-18 01:02:32 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-18 01:02:26 ----D---- C:\Program Files\Common Files\InstallShield
2009-01-18 00:40:39 ----D---- C:\Documents and Settings\Jason\Application Data\Macromedia
2009-01-18 00:39:39 ----D---- C:\Documents and Settings\Jason\Application Data\Adobe
2009-01-17 00:27:01 ----A---- C:\WINDOWS\system32\javaws.exe
2009-01-17 00:27:01 ----A---- C:\WINDOWS\system32\javaw.exe
2009-01-17 00:27:01 ----A---- C:\WINDOWS\system32\java.exe
2009-01-17 00:27:01 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-01-16 21:18:30 ----SHD---- C:\RECYCLER
2009-01-16 20:24:46 ----D---- C:\Program Files\Xilisoft
2009-01-16 20:14:46 ----D---- C:\Documents and Settings\Jason\Application Data\vlc
2009-01-16 20:14:06 ----D---- C:\Program Files\VideoLAN
2009-01-16 20:13:43 ----D---- C:\Program Files\CCleaner
2009-01-16 20:11:53 ----D---- C:\Program Files\VS Revo Group
2009-01-16 20:06:39 ----A---- C:\WINDOWS\system32\msonpmon.dll
2009-01-16 20:04:54 ----D---- C:\Program Files\Microsoft Works
2009-01-16 20:04:44 ----D---- C:\Program Files\MSBuild
2009-01-16 20:04:24 ----D---- C:\Program Files\Microsoft Visual Studio
2009-01-16 20:04:24 ----D---- C:\Program Files\Common Files\DESIGNER
2009-01-16 20:01:05 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-16 20:00:39 ----D---- C:\Program Files\SUPERAntiSpyware
2009-01-16 20:00:39 ----D---- C:\Documents and Settings\Jason\Application Data\SUPERAntiSpyware.com
2009-01-16 20:00:38 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-01-16 20:00:27 ----A---- C:\WINDOWS\system32\MSSTDFMT.DLL
2009-01-16 20:00:26 ----D---- C:\Program Files\SpywareBlaster
2009-01-16 19:59:45 ----D---- C:\WINDOWS\SHELLNEW
2009-01-16 19:59:23 ----D---- C:\Program Files\Microsoft Office
2009-01-16 19:59:23 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-01-16 19:59:02 ----RHD---- C:\MSOCache
2009-01-16 19:57:08 ----D---- C:\WINDOWS\system32\PreInstall
2009-01-16 19:57:07 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2009-01-16 19:57:07 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-16 19:23:48 ----D---- C:\Program Files\Lavasoft
2009-01-16 19:23:47 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-01-16 19:23:30 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-01-16 19:18:11 ----D---- C:\WINDOWS\system32\NtmsData
2009-01-16 18:53:46 ----A---- C:\WINDOWS\system32\MSVCR71.dll
2009-01-16 18:53:46 ----A---- C:\WINDOWS\system32\MSVCP71.dll
2009-01-16 18:53:46 ----A---- C:\WINDOWS\system32\MFC71.dll
2009-01-16 18:53:46 ----A---- C:\WINDOWS\system32\aswBoot.exe
2009-01-16 18:53:41 ----D---- C:\Program Files\Alwil Software
2009-01-16 18:51:39 ----D---- C:\Documents and Settings\Jason\Application Data\Styler
2009-01-16 18:51:23 ----D---- C:\Documents and Settings\Jason\Application Data\Identities
2009-01-16 18:51:21 ----HD---- C:\Program Files\Uninstall Information
2009-01-16 18:50:19 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-01-16 18:50:10 ----ASH---- C:\Documents and Settings\Jason\Application Data\desktop.ini
2009-01-16 18:50:03 ----SD---- C:\Documents and Settings\Jason\Application Data\Microsoft
2009-01-16 18:50:03 ----D---- C:\Documents and Settings\Jason\Application Data\WinRAR
2009-01-16 18:50:03 ----D---- C:\Documents and Settings\Jason\Application Data\Sun
2009-01-16 18:49:12 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-01-16 18:39:28 ----D---- C:\WINDOWS\SoftwareDistribution
2009-01-16 18:39:15 ----SD---- C:\WINDOWS\system32\Microsoft
2009-01-16 18:39:15 ----D---- C:\WINDOWS\Prefetch
2009-01-16 18:39:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-16 18:37:47 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-01-16 18:37:46 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-01-16 18:37:35 ----A---- C:\WINDOWS\system32\wmpns.dll
2009-01-16 18:37:32 ----D---- C:\Program Files\Windows Media Connect 2
2009-01-16 18:37:26 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-01-16 18:36:59 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-01-16 18:36:40 ----D---- C:\WINDOWS\system32\LogFiles
2009-01-16 18:36:37 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-01-16 18:35:41 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-01-16 18:35:29 ----D---- C:\Program Files\Alky for Applications
2009-01-16 18:34:42 ----D---- C:\Program Files\Kristanix
2009-01-16 18:34:41 ----D---- C:\WINDOWS\Resource Hacker 3.4.0
2009-01-16 18:34:41 ----D---- C:\Program Files\Resource Hacker 3.4.0
2009-01-16 18:33:51 ----D---- C:\Program Files\Java
2009-01-16 18:33:50 ----D---- C:\Program Files\Common Files\Java
2009-01-16 18:27:30 ----A---- C:\WINDOWS\control.ini
2009-01-16 18:27:30 ----A---- C:\AUTOEXEC.BAT
2009-01-16 18:27:18 ----A---- C:\WINDOWS\OEWABLog.txt
2009-01-16 18:27:13 ----D---- C:\WINDOWS\system32\dllcache
2009-01-16 18:27:13 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-01-16 18:26:14 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-01-16 18:26:09 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-01-16 18:26:04 ----HD---- C:\Program Files\WindowsUpdate
2009-01-16 18:25:59 ----D---- C:\Program Files\Online Services
2009-01-16 18:25:45 ----A---- C:\WINDOWS\system32\desktop.ini
2009-01-16 18:25:45 ----A---- C:\WINDOWS\system32\atrace.dll
2009-01-16 18:25:45 ----A---- C:\WINDOWS\desktop.ini
2009-01-16 18:25:41 ----A---- C:\WINDOWS\system32\acctres.dll
2009-01-16 18:25:40 ----D---- C:\Program Files\Common Files\Services
2009-01-16 18:25:38 ----SD---- C:\WINDOWS\Tasks
2009-01-16 18:25:38 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-01-16 18:25:37 ----D---- C:\Program Files\Common Files\MSSoap
2009-01-16 18:25:34 ----D---- C:\WINDOWS\srchasst
2009-01-16 18:25:33 ----D---- C:\WINDOWS\system32\Macromed
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wups.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuaueng.dll.wusetup.633250.bak
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuaucpl.cpl.wusetup.633187.bak
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuauclt.exe.wusetup.633078.bak
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\wuapi.dll.wusetup.633015.bak
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-01-16 18:25:27 ----D---- C:\Program Files\Movie Maker
2009-01-16 18:25:11 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-01-16 18:25:11 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-01-16 18:25:11 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-01-16 18:25:11 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-01-16 18:25:07 ----D---- C:\WINDOWS\system32\Restore
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\srclient.dll
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-01-16 18:25:06 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-01-16 18:25:06 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-01-16 18:25:05 ----A---- C:\WINDOWS\system32\inetres.dll
2009-01-16 18:25:05 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-01-16 18:25:04 ----D---- C:\Program Files\Outlook Express
2009-01-16 18:25:04 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\mstask.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\isign32.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-01-16 18:24:58 ----D---- C:\Program Files\Common Files\System
2009-01-16 18:24:18 ----D---- C:\Program Files\ComPlus Applications
2009-01-16 18:24:16 ----A---- C:\WINDOWS\vbaddin.ini
2009-01-16 18:24:16 ----A---- C:\WINDOWS\vb.ini
2009-01-16 18:24:12 ----D---- C:\WINDOWS\Registration
2009-01-16 18:24:04 ----D---- C:\Program Files\Windows Media Player
2009-01-16 18:23:56 ----A---- C:\WINDOWS\system32\advpack.dll.mui
2009-01-16 18:23:53 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-16 18:23:53 ----RD---- C:\WINDOWS\Offline Web Pages
2009-01-16 18:23:53 ----A---- C:\WINDOWS\system32\winfxdocobj.exe
2009-01-16 18:23:52 ----A---- C:\WINDOWS\system32\msfeedssync.exe
2009-01-16 18:23:51 ----D---- C:\WINDOWS\wbem
2009-01-16 18:23:51 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-01-16 18:23:50 ----A---- C:\WINDOWS\system32\ieframe.dll.mui
2009-01-16 18:23:48 ----D---- C:\Program Files\Internet Explorer
2009-01-16 18:21:54 ----D---- C:\Program Files\VistaExperience.org
2009-01-16 18:20:09 ----D---- C:\Program Files\Windows Sidebar
2009-01-16 18:20:00 ----D---- C:\Program Files\Styler
2009-01-16 18:19:44 ----A---- C:\WINDOWS\system32\msvcr80.dll
2009-01-16 18:19:43 ----A---- C:\WINDOWS\system32\engine.dll
2009-01-16 18:19:41 ----D---- C:\Program Files\Desktop
2009-01-16 18:19:40 ----A---- C:\WINDOWS\system32\CabTool.exe
2009-01-16 18:18:53 ----D---- C:\Program Files\WinRAR
2009-01-16 18:18:45 ----D---- C:\Program Files\LClock
2009-01-16 18:18:43 ----D---- C:\Program Files\HashTab Shell Extension
2009-01-16 18:18:42 ----D---- C:\Program Files\Unlocker
2009-01-16 18:18:42 ----D---- C:\Program Files\Microsoft PowerToys
2009-01-16 18:18:42 ----A---- C:\WINDOWS\system32\write.exe
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\hticons.dll
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\avwav.dll
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-01-16 18:18:40 ----A---- C:\WINDOWS\system32\winchat.exe
2009-01-16 18:18:39 ----A---- C:\WINDOWS\system32\getuname.dll
2009-01-16 18:18:39 ----A---- C:\WINDOWS\system32\charmap.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tskill.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tscon.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\shadow.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\reset.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\regini.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\calc.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\msg.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\logoff.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-01-16 18:18:33 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-01-16 18:18:32 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-01-16 18:18:32 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-01-16 18:18:32 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-01-16 18:18:31 ----D---- C:\WINDOWS\system32\en-US
2009-01-16 18:18:31 ----D---- C:\Program Files\Windows NT
2009-01-16 18:18:31 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-01-16 18:18:31 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-01-16 18:18:30 ----A---- C:\WINDOWS\system32\tsgqec.dll
2009-01-16 18:18:30 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-01-16 18:18:30 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2009-01-16 18:18:30 ----A---- C:\WINDOWS\system32\aaclient.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-01-16 18:18:28 ----D---- C:\WINDOWS\system32\MsDtc
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-01-16 18:18:27 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-01-16 18:18:27 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-01-16 18:18:27 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-01-16 18:18:27 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-01-16 18:18:26 ----D---- C:\WINDOWS\system32\Com
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\stclient.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\colbact.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\comuid.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-01-16 18:18:20 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-01-16 18:18:20 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-01-16 18:18:20 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-01-16 18:18:20 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-01-16 18:15:00 ----A---- C:\WINDOWS\system32\h323log.txt
2009-01-16 17:59:59 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-01-16 17:59:03 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2009-01-16 17:59:02 ----A---- C:\WINDOWS\system32\ati3duag.dll
2009-01-16 17:59:02 ----A---- C:\WINDOWS\system32\ati3d1ag.dll
2009-01-16 17:59:02 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2009-01-16 17:59:02 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2009-01-16 17:58:31 ----A---- C:\WINDOWS\system32\usbui.dll
2009-01-16 17:56:28 ----A---- C:\WINDOWS\imsins.BAK
2009-01-16 17:56:25 ----SHD---- C:\WINDOWS\Installer
2009-01-16 17:56:25 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-16 17:56:24 ----D---- C:\Program Files\Common Files\ODBC
2009-01-16 17:56:24 ----A---- C:\WINDOWS\ODBCINST.INI
2009-01-16 17:56:21 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-01-16 17:56:20 ----RD---- C:\Program Files
2009-01-16 17:56:20 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-01-16 17:56:20 ----D---- C:\Program Files\Common Files
2009-01-16 17:56:17 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-01-16 17:56:17 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-01-16 17:56:17 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-01-16 17:56:05 ----A---- C:\WINDOWS\system32\irclass.dll
2009-01-16 17:56:05 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-01-16 17:56:05 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-01-16 17:56:04 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-01-16 17:56:04 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-01-16 17:56:02 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-01-16 17:56:02 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-01-16 17:56:01 ----A---- C:\WINDOWS\system32\storprop.dll
2009-01-16 17:56:01 ----A---- C:\WINDOWS\system32\batt.dll
2009-01-16 17:56:01 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-01-16 17:55:52 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-01-16 17:55:44 ----RA---- C:\WINDOWS\SET8.tmp
2009-01-16 17:55:41 ----RA---- C:\WINDOWS\SET4.tmp
2009-01-16 17:55:40 ----RA---- C:\WINDOWS\SET3.tmp
2009-01-16 17:55:35 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-16 17:55:35 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-16 17:55:29 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-16 17:55:15 ----A---- C:\WINDOWS\setuplog.txt
2009-01-16 17:54:02 ----A---- C:\WINDOWS\system32\NicInst.dll
2009-01-16 17:54:02 ----A---- C:\WINDOWS\system32\NicCo2.dll
2009-01-16 17:54:02 ----A---- C:\WINDOWS\system32\e100bmsg.dll
2009-01-16 17:53:28 ----D---- C:\Documents and Settings
2009-01-16 17:53:27 ----SHD---- C:\System Volume Information
2009-01-16 17:53:02 ----SH---- C:\boot.ini
2009-01-16 17:49:39 ----RSD---- C:\WINDOWS\Fonts
2009-01-16 17:49:39 ----RD---- C:\WINDOWS\Web
2009-01-16 17:49:39 ----HD---- C:\WINDOWS\inf
2009-01-16 17:49:39 ----D---- C:\WINDOWS\WinSxS
2009-01-16 17:49:39 ----D---- C:\WINDOWS\twain_32
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Temp
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\wins
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\wbem
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\usmt
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\spool
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\ShellExt
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\Setup
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\scripting
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\ras
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\oobe
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\npp
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\mui
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\inetsrv
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\IME
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\icsxml
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\ias
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\export
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\en
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\drivers
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\dhcp
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\config
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\3com_dmi
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\3076
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\2052
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1054
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1042
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1041
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1037
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1033
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1031
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1028
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1025
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system
2009-01-16 17:49:39 ----D---- C:\WINDOWS\security
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Resources
2009-01-16 17:49:39 ----D---- C:\WINDOWS\repair
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Provisioning
2009-01-16 17:49:39 ----D---- C:\WINDOWS\PeerNet
2009-01-16 17:49:39 ----D---- C:\WINDOWS\pchealth
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Network Diagnostic
2009-01-16 17:49:39 ----D---- C:\WINDOWS\mui
2009-01-16 17:49:39 ----D---- C:\WINDOWS\msapps
2009-01-16 17:49:39 ----D---- C:\WINDOWS\msagent
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Media
2009-01-16 17:49:39 ----D---- C:\WINDOWS\L2Schemas
2009-01-16 17:49:39 ----D---- C:\WINDOWS\java
2009-01-16 17:49:39 ----D---- C:\WINDOWS\ime
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Help
2009-01-16 17:49:39 ----D---- C:\WINDOWS\ehome
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Driver Cache
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Debug
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Cursors
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Connection Wizard
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Config
2009-01-16 17:49:39 ----D---- C:\WINDOWS\AppPatch
2009-01-16 17:49:39 ----D---- C:\WINDOWS\addins
2009-01-16 17:49:39 ----D---- C:\WINDOWS
2009-01-08 03:14:40 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-01-08 03:14:40 ----A---- C:\WINDOWS\system32\pncrt.dll

======List of files/folders modified in the last 1 months======

2009-01-16 20:00:00 ----A---- C:\WINDOWS\win.ini
2009-01-16 17:56:20 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2007-12-04 26624]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2007-12-04 42912]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2007-12-04 94544]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-06-19 60800]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2007-12-04 23152]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-04-14 701440]
R3 BCMModem;BCM V.90 56K Modem; C:\WINDOWS\system32\DRIVERS\BCMDM.sys [2001-08-17 871388]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2006-08-11 502272]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2006-08-11 499584]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2006-08-11 7168]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\drivers\ctsfm2k.sys [2006-08-11 143872]
R3 E100B;Intel® PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2007-11-16 165496]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2006-08-11 78336]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2006-08-11 766976]
R3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\system32\drivers\hap16v2k.sys [2006-08-11 154112]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-06-19 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-06-19 61824]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2006-08-11 116224]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\system32\drivers\ctdvda2k.sys [2005-11-10 340704]
S3 hap17v2k;Creative P17V HAL Driver; C:\WINDOWS\system32\drivers\hap17v2k.sys [2006-08-11 180224]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-05-12 611664]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2007-12-04 17272]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2007-12-04 140664]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-17 152984]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2007-12-04 247160]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2007-12-04 345464]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------




info.txt:

info.txt logfile of random's system information tool 1.05 2009-02-07 23:54:09

======Uninstall list======

-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Alky for Applications (Windows XP)-->MsiExec.exe /X{BB05D173-9681-4812-A7FA-BD4042A3DA00}
avast! Antivirus-->rundll32 C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Creative Audio Console-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9 /remove
[bleep] NFO Viewer v2.10.0032.RC3 (Remove Only)-->rundll32.exe advpack.dll,LaunchINFSection DamnNFO.inf,DefaultUninstall
Guild Wars-->"C:\Program Files\Guild Wars\Gw.exe" -uninstall
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Java™ 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java™ 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
LClock-->C:\Program Files\LClock\Uninstall.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office 2007 Recent Documents Gadget-->MsiExec.exe /X{90120000-008A-0409-0000-0000000FF1CE}
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 SP1 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30304-->MsiExec.exe /X{C9B26742-06BE-3B75-B1DE-7B91B5956A04}
Resource Hacker 3.4.0-->"C:\WINDOWS\Resource Hacker 3.4.0\uninstall.exe" "/U:C:\Program Files\Resource Hacker 3.4.0\Uninstall\uninstall.xml"
Revo Uninstaller 1.75-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
Right Click Image Converter-->"C:\Program Files\Kristanix\Right Click Image Converter\uninstall.exe"
SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
Styler-->MsiExec.exe /I{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Unlocker 1.8.5-->C:\Program Files\Unlocker\uninst.exe
Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
VideoLAN VLC media player 0.8.6i-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Sidebar-->RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,UnInstall
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
Xilisoft Video Converter Ultimate-->C:\Program Files\Xilisoft\Video Converter Ultimate\Uninstall.exe

======Security center information======

AV: avast! antivirus 4.7.1098 [VPS 090207-0]

System event log

Computer Name: DOWNSTAIRS
Event Code: 15007
Message: Reservation for namespace identified by URL prefix http://*:2869/ was successfully added.

Record Number: 5
Source Name: HTTP
Time Written: 20090116182602.000000+000
Event Type: information
User:

Computer Name: DOWNSTAIRS
Event Code: 6011
Message: The NetBIOS name and DNS host name of this machine have been changed from MACHINENAME to DOWNSTAIRS.

Record Number: 4
Source Name: EventLog
Time Written: 20090116181520.000000+000
Event Type: information
User:

Computer Name: MACHINENAME
Event Code: 2
Message: While validating that \Device\Serial0 was really a serial port, a fifo was detected. The fifo will be used.

Record Number: 3
Source Name: Serial
Time Written: 20090116175352.000000+000
Event Type: information
User:

Computer Name: MACHINENAME
Event Code: 6005
Message: The Event log service was started.

Record Number: 2
Source Name: EventLog
Time Written: 20090116175335.000000+000
Event Type: information
User:

Computer Name: MACHINENAME
Event Code: 6009
Message: Microsoft ® Windows ® 5.01. 2600 Service Pack 3 Multiprocessor Free.

Record Number: 1
Source Name: EventLog
Time Written: 20090116175335.000000+000
Event Type: information
User:

Application event log

Computer Name: DOWNSTAIRS
Event Code: 1000
Message: Performance counters for the MSDTC (MSDTC) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.

Record Number: 5
Source Name: LoadPerf
Time Written: 20090116182407.000000+000
Event Type: information
User:

Computer Name: DOWNSTAIRS
Event Code: 1000
Message: Performance counters for the TermService (Terminal Services) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.

Record Number: 4
Source Name: LoadPerf
Time Written: 20090116182404.000000+000
Event Type: information
User:

Computer Name: DOWNSTAIRS
Event Code: 1000
Message: Performance counters for the RemoteAccess (Routing and Remote Access) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.

Record Number: 3
Source Name: LoadPerf
Time Written: 20090116181608.000000+000
Event Type: information
User:

Computer Name: DOWNSTAIRS
Event Code: 1000
Message: Performance counters for the PSched (PSched) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.

Rest of info.txt in next post

Edited by Jason1230, 07 February 2009 - 06:03 PM.

  • 0

#4
Jason1230

Jason1230

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
info.txt (Part 2):

Record Number: 2
Source Name: LoadPerf
Time Written: 20090116181548.000000+000
Event Type: information
User:

Computer Name: DOWNSTAIRS
Event Code: 1000
Message: Performance counters for the RSVP (QoS RSVP) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.

Record Number: 1
Source Name: LoadPerf
Time Written: 20090116181528.000000+000
Event Type: information
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Alky for Applications\Libraries\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------
  • 0

#5
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
could be a video card issue, but lets run through some steps to make sure:

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review and a new hijackthis log

andrewuk
  • 0

#6
Jason1230

Jason1230

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
C:\ComboFix.txt:


ComboFix 09-02-07.01 - Jason 2009-02-08 18:37:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.237 [GMT 0:00]
Running from: c:\documents and settings\Jason\Desktop\ComboFix.exe
AV: avast! antivirus 4.7.1098 [VPS 090208-0] *On-access scanning enabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-01-08 to 2009-02-08 )))))))))))))))))))))))))))))))
.

2009-02-07 23:53 . 2009-02-07 23:54 <DIR> d-------- C:\rsit
2009-02-02 22:18 . 2009-02-02 22:18 <DIR> d-------- c:\program files\Guild Wars
2009-01-31 13:58 . 2009-01-31 13:58 <DIR> d-------- c:\program files\Trend Micro
2009-01-25 20:33 . 2009-01-25 20:33 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-01-25 20:32 . 2009-01-25 20:33 <DIR> d-------- c:\program files\Common Files\Adobe
2009-01-25 20:24 . 2009-01-28 21:37 <DIR> d-------- c:\program files\NOS
2009-01-25 20:24 . 2009-01-28 21:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2009-01-18 11:32 . 2009-01-18 11:32 <DIR> d-------- c:\windows\Sun
2009-01-18 01:08 . 2009-02-08 18:26 4,958,588 --a------ c:\windows\{00000002-00000000-00000000-00001102-00000004-10031102}.BAK
2009-01-18 01:08 . 2009-02-08 00:05 30,912 --a------ c:\windows\system32\BMXStateBkp-{00000002-00000000-00000000-00001102-00000004-10031102}.rfx
2009-01-18 01:08 . 2009-02-08 00:05 30,912 --a------ c:\windows\system32\BMXState-{00000002-00000000-00000000-00001102-00000004-10031102}.rfx
2009-01-18 01:08 . 2009-02-08 00:05 30,120 --a------ c:\windows\system32\BMXCtrlState-{00000002-00000000-00000000-00001102-00000004-10031102}.rfx
2009-01-18 01:08 . 2009-02-08 00:05 30,120 --a------ c:\windows\system32\BMXBkpCtrlState-{00000002-00000000-00000000-00001102-00000004-10031102}.rfx
2009-01-18 01:08 . 2009-02-08 00:05 11,564 --a------ c:\windows\system32\DVCState-{00000002-00000000-00000000-00001102-00000004-10031102}.rfx
2009-01-18 01:08 . 2009-02-08 00:05 1,080 --a------ c:\windows\system32\settingsbkup.sfm
2009-01-18 01:08 . 2009-02-08 00:05 1,080 --a------ c:\windows\system32\settings.sfm
2009-01-18 01:04 . 2009-01-18 01:11 <DIR> d-------- c:\windows\system32\Defaults
2009-01-18 01:04 . 2009-02-08 18:26 4,958,588 --a------ c:\windows\{00000002-00000000-00000000-00001102-00000004-10031102}.CDF
2009-01-18 01:04 . 2000-12-05 09:11 4,174,814 --------- c:\windows\system32\CT4MGM.SF2
2009-01-18 01:04 . 2008-04-14 05:15 6,272 --a------ c:\windows\system32\drivers\splitter.sys
2009-01-18 01:03 . 2009-01-18 01:03 <DIR> d-------- c:\documents and settings\Jason\Application Data\Creative
2009-01-18 01:03 . 2009-01-18 01:03 409,600 --a------ c:\windows\system32\wrap_oal.dll
2009-01-18 01:03 . 2008-04-14 05:15 172,416 --a------ c:\windows\system32\drivers\kmixer.sys
2009-01-18 01:03 . 2008-04-14 05:49 146,048 --a------ c:\windows\system32\drivers\portcls.sys
2009-01-18 01:03 . 2008-04-14 03:09 142,592 --a------ c:\windows\system32\drivers\aec.sys
2009-01-18 01:03 . 2009-01-18 01:03 86,016 --a------ c:\windows\system32\OpenAL32.dll
2009-01-18 01:03 . 2008-04-14 05:47 83,072 --a------ c:\windows\system32\drivers\wdmaud.sys
2009-01-18 01:03 . 2008-04-14 05:45 60,800 --a------ c:\windows\system32\drivers\sysaudio.sys
2009-01-18 01:03 . 2008-04-14 05:15 60,160 --a------ c:\windows\system32\drivers\drmk.sys
2009-01-18 01:03 . 2008-04-14 05:15 56,576 --a------ c:\windows\system32\drivers\swmidi.sys
2009-01-18 01:03 . 2008-04-14 05:15 52,864 --a------ c:\windows\system32\drivers\DMusic.sys
2009-01-18 01:03 . 2008-04-14 05:15 2,944 --a------ c:\windows\system32\drivers\drmkaud.sys
2009-01-18 01:02 . 2009-01-18 01:03 <DIR> d-------- c:\windows\system32\Data
2009-01-18 01:02 . 2009-01-18 01:04 <DIR> d--h----- c:\program files\InstallShield Installation Information
2009-01-18 01:02 . 2009-01-18 01:04 <DIR> d-------- c:\program files\Creative
2009-01-18 01:02 . 2009-01-18 01:02 <DIR> d-------- c:\program files\Common Files\InstallShield
2009-01-18 01:02 . 2006-08-11 15:14 86,446 --a------ c:\windows\system32\instwdm.ini
2009-01-18 01:02 . 2006-08-11 14:57 11,776 --a------ c:\windows\INRES.DLL
2009-01-18 01:02 . 2006-08-11 14:55 10,240 --a------ c:\windows\CTDCRES.DLL
2009-01-18 01:02 . 2006-08-11 14:56 3,072 --a------ c:\windows\CTXFIRES.DLL
2009-01-18 01:02 . 2006-08-11 14:32 191 --a------ c:\windows\system32\ctzapxx.ini
2009-01-17 00:27 . 2009-01-17 00:26 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-16 20:24 . 2009-01-16 20:24 <DIR> d-------- c:\program files\Xilisoft
2009-01-16 20:14 . 2009-01-16 20:14 <DIR> d-------- c:\program files\VideoLAN
2009-01-16 20:14 . 2009-01-16 20:14 <DIR> d-------- c:\documents and settings\Jason\Application Data\vlc
2009-01-16 20:13 . 2009-01-16 20:13 <DIR> d-------- c:\program files\CCleaner
2009-01-16 20:11 . 2009-01-16 20:11 <DIR> d-------- c:\program files\VS Revo Group
2009-01-16 20:06 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2009-01-16 20:04 . 2009-01-16 20:04 <DIR> d-------- c:\program files\MSBuild
2009-01-16 20:04 . 2009-01-16 20:04 <DIR> d-------- c:\program files\Microsoft Works
2009-01-16 20:01 . 2009-01-16 20:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-16 20:00 . 2009-01-24 22:30 <DIR> d-------- c:\program files\SUPERAntiSpyware
2009-01-16 20:00 . 2009-01-24 22:30 <DIR> d-------- c:\program files\SpywareBlaster
2009-01-16 20:00 . 2009-01-16 20:00 <DIR> d-------- c:\documents and settings\Jason\Application Data\SUPERAntiSpyware.com
2009-01-16 20:00 . 2009-01-24 22:30 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-01-16 20:00 . 2005-04-15 20:58 1,071,088 --a------ c:\windows\system32\MSCOMCTL.OCX
2009-01-16 20:00 . 2005-08-25 19:18 118,784 --a------ c:\windows\system32\MSSTDFMT.DLL
2009-01-16 19:59 . 2009-01-16 20:04 <DIR> d-------- c:\windows\SHELLNEW
2009-01-16 19:59 . 2009-01-16 19:59 <DIR> dr-h----- C:\MSOCache
2009-01-16 19:59 . 2009-01-16 20:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-16 19:57 . 2009-01-16 20:25 <DIR> d--h----- c:\windows\$hf_mig$
2009-01-16 19:23 . 2009-01-16 19:23 <DIR> d-------- c:\program files\Lavasoft
2009-01-16 19:23 . 2009-01-16 20:00 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-01-16 19:23 . 2009-01-16 19:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-16 19:18 . 2009-01-16 19:21 <DIR> d-------- c:\windows\system32\NtmsData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-17 00:26 --------- d-----w c:\program files\Java
2009-01-16 18:53 --------- d-----w c:\program files\Alwil Software
2009-01-16 18:51 --------- d-----w c:\program files\Styler
2009-01-16 18:51 --------- d-----w c:\documents and settings\Jason\Application Data\Styler
2009-01-16 18:37 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-16 18:35 --------- d-----w c:\program files\Windows Sidebar
2009-01-16 18:35 --------- d-----w c:\program files\Alky for Applications
2009-01-16 18:34 --------- d-----w c:\program files\Resource Hacker 3.4.0
2009-01-16 18:34 --------- d-----w c:\program files\Kristanix
2009-01-16 18:33 --------- d-----w c:\program files\Common Files\Java
2009-01-16 18:21 --------- d-----w c:\program files\VistaExperience.org
2009-01-16 18:20 --------- d-----w c:\program files\Unlocker
2009-01-16 18:19 --------- d-----w c:\program files\Desktop
2009-01-16 18:18 --------- d-----w c:\program files\Microsoft PowerToys
2009-01-16 18:18 --------- d-----w c:\program files\LClock
2009-01-16 18:18 --------- d-----w c:\program files\HashTab Shell Extension
.

------- Sigcheck -------

2008-06-19 20:43 361344 68f06fe0021b01e670af37b8c5964fdf c:\windows\system32\drivers\tcpip.sys

2008-08-14 10:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2GDR\ntoskrnl.exe
2008-08-14 09:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2QFE\ntoskrnl.exe
2008-08-14 10:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3GDR\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3QFE\ntoskrnl.exe
2008-04-23 05:58 2306560 8c4050bd9fd87e23cded28ffa889b0ba c:\windows\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-03-22 1271808]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-24 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-17 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 79224]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"CTHelper"="CTHELPER.EXE" [2006-08-11 c:\windows\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 c:\windows\system32\CTXFIHLP.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [2008-06-19 c:\windows\system32\advpack.dll]

c:\documents and settings\Jason\Start Menu\Programs\Startup\
Styler.lnk - c:\documents and settings\Jason\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [1/16/2009 6:50:21 PM 15086]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/22/2008 11:06:00 AM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/22/2008 11:05:58 AM 55024]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/22/2008 11:06:02 AM 7408]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.yahoo.com/?p=us
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-08 18:37:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(700)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-02-08 18:38:50
ComboFix-quarantined-files.txt 2009-02-08 18:38:48

Pre-Run: 96,491,417,600 bytes free
Post-Run: 96,691,380,224 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

174 --- E O F --- 2009-01-16 19:57:12





HijackThis Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:45:37, on 08/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Styler\Styler.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/?p=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Styler.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 5474 bytes
  • 0

#7
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
i cant see anything yet, lets scan a couple of files and do a couple of general scans to see what comes out.

what program did you download?


the scans will likely take 3 hours, quite possibly much longer. so just let them run.


====STEP 1====
Please download ATF Cleaner by Atribune.

Caution: This program is for Windows 2000, XP and Vista only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


====STEP 2====
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



====STEP 3====
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan"box on the top of the page:

    • c:\windows\system32\drivers\tcpip.sys
  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply (you will need to paste the link onto a notepad before you do the other scans below, else the contents of your clipboard will be written over with the new links).
Could you do the same for the following files:
  • c:\windows\system32\ntoskrnl.exe



====STEP 4====
Please do an online scan with Kaspersky WebScanner (this will identify any issues, we will clear them in the following post)

Kaspersky online scanner uses JAVA tecnology to perform the scan. If you do not have the latest JAVA version, follow the instrutions below under Upgrading Java, to download and install the latest vesion.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE) 6 Update 12.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u11-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u11-windows-i586-p.exe and select "Run as an Administrator.")
In your next reply could i see:
1. the answer to the question on the program downloaded
2. the malarebytes log
3. the 2 virscan logs or links
4. the kaspersky log

The text from these files may exceed the maximum post length for this forum. Hence, you may need to post the information over 2 or more posts.

andrewuk
  • 0

#8
Jason1230

Jason1230

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
I downloaded SuperAntiSpyware from an anomalous site, which i think is where the possible virus came from. The program worked fine at first, but the computer was running a bit slow. Then I restarted my computer and the lines appeared.

I tried a virus scan on Avast! Pro Edition but nothing came up. After a long consideration, I decided to do a reinstall of Windows XP because I couldn't stand these lines and I didn't have anything important on the computer at the time.

However even after this, the lines still appeared, and so I downloaded SuperAntiSpyware Free Edition from the official website this time, Avast! Pro Edition, Spyware Blaster and Ad-Aware; and did scans on them, again nothing came up.

I gave up trying to solve it myself and so I posted this problem here hoping someone would help me out :)

Since I did a reinstall of Windows XP, I was beginning to think it is a video card issue, but since it happened after restarting after downloading the program, I still wasn't sure which was the problem.

However after running all these scans you suggested and none of them reported any threats, I now believe it to be a video card issue and hope that you can tell me what to do to fix it :)

But nevertheless, here are the logs:



Malarebytes Log:

Malwarebytes' Anti-Malware 1.33
Database version: 1743
Windows 5.1.2600 Service Pack 3

10/02/2009 20:00:55
mbam-log-2009-02-10 (20-00-55).txt

Scan type: Full Scan (C:\|)
Objects scanned: 76816
Time elapsed: 1 hour(s), 42 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




c:\windows\system32\drivers\tcpip.sys Virscan Log:

VirSCAN.org Scanned Report :
Scanned time : 2009/02/10 17:51:04 (GMT)
Scanner results: All Scanners reported not find malware!
File Name : tcpip.sys
File Size : 361344 byte
File Type : PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5 : 68f06fe0021b01e670af37b8c5964fdf
SHA1 : 0293bc3265f61339323fb71005b84dc6df0a9eb3
Online report : http://virscan.org/r...9f2d1dc9f2.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090209183317 2009-02-09 2.32 -
AhnLab V3 2009.02.10.03 2009.02.10 2009-02-10 1.45 -
AntiVir 7.9.0.76 7.1.2.5 2009-02-10 1.94 -
Antiy 2.0.18 20090210.2177933 2009-02-10 0.12 -
Authentium 5.1.1 200902101537 2009-02-10 1.08 -
AVAST! 3.0.1 090209-0 2009-02-09 0.02 -
AVG 7.5.52.442 270.10.20/1943 2009-02-10 1.90 -
BitDefender 7.81008.2640284 7.23599 2009-02-11 2.47 -
CA (VET) 9.0.0.143 31.6.6348 2009-02-10 5.83 -
ClamAV 0.94.2 8976 2009-02-10 0.08 -
Comodo 3.0 973 2009-02-10 0.93 -
CP Secure 1.1.0.715 2009.02.11 2009-02-11 6.82 -
Dr.Web 4.44.0.9170 2009.02.10 2009-02-10 4.25 -
F-Prot 4.4.4.56 20090210 2009-02-10 1.13 -
F-Secure 5.51.6100 2009.02.10.10 2009-02-10 0.06 -
Fortinet 2.81-3.117 10.19 2009-02-10 0.18 -
GData 19.2974/19.219 20090210 2009-02-10 3.95 -
ViRobot 20090209 2009.02.09 2009-02-09 0.78 -
Ikarus T3.1.01.45 2009.02.10.72283 2009-02-10 3.68 -
JiangMin 11.0.706 2009.02.10 2009-02-10 1.45 -
Kaspersky 5.5.10 2009.02.10 2009-02-10 0.04 -
KingSoft 2008.9.8.18 2009.2.10.22 2009-02-10 0.61 -
McAfee 5.3.00 5521 2009-02-09 3.20 -
Microsoft 1.4306 2009.02.10 2009-02-10 4.37 -
mks_vir 2.01 2009.02.09 2009-02-09 2.97 -
Norman 6.00.02 6.00.00 2009-02-09 8.01 -
Panda 9.05.01 2009.02.09 2009-02-09 2.44 -
Trend Micro 8.700-1004 5.829.00 2009-02-10 0.03 -
Quick Heal 10.00 2009.02.10 2009-02-10 1.02 -
Rising 20.0 21.16.12.00 2009-02-10 0.80 -
Sophos 2.83.3 4.38 2009-02-11 2.33 -
Sunbelt 4804 4804 2009-02-06 0.50 -
Symantec 1.3.0.24 20090210.003 2009-02-10 0.34 -
nProtect 20090210.07 3118216 2009-02-10 3.78 -
The Hacker 6.3.1.5 v00250 2009-02-09 0.55 -
VBA32 3.12.8.12 20090210.0906 2009-02-10 1.72 -
VirusBuster 4.5.11.10 10.101.8/894840 2009-02-10 1.20 -





c:\windows\system32\ntoskrnl.exe Virscan Log:

VirSCAN.org Scanned Report :
Scanned time : 2009/02/10 17:55:36 (GMT)
Scanner results: All Scanners reported not find malware!
File Name : ntoskrnl.exe
File Size : 2306560 byte
File Type : PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5 : 8c4050bd9fd87e23cded28ffa889b0ba
SHA1 : bab9fe9552925158895966922e50a458867d080c
Online report : http://virscan.org/r...65be531f59.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090209183317 2009-02-09 2.25 -
AhnLab V3 2009.02.10.03 2009.02.10 2009-02-10 1.20 -
AntiVir 7.9.0.76 7.1.2.5 2009-02-10 1.96 -
Antiy 2.0.18 20090210.2177933 2009-02-10 0.12 -
Authentium 5.1.1 200902101537 2009-02-10 1.48 -
AVAST! 3.0.1 090209-0 2009-02-09 0.12 -
AVG 7.5.52.442 270.10.20/1943 2009-02-10 1.90 -
BitDefender 7.81008.2640284 7.23599 2009-02-11 2.47 -
CA (VET) 9.0.0.143 31.6.6348 2009-02-10 5.29 -
ClamAV 0.94.2 8976 2009-02-10 0.49 -
Comodo 3.0 973 2009-02-10 0.92 -
CP Secure 1.1.0.715 2009.02.11 2009-02-11 6.93 -
Dr.Web 4.44.0.9170 2009.02.10 2009-02-10 4.56 -
F-Prot 4.4.4.56 20090210 2009-02-10 1.40 -
F-Secure 5.51.6100 2009.02.10.10 2009-02-10 0.11 -
Fortinet 2.81-3.117 10.19 2009-02-10 0.23 -
GData 19.2974/19.219 20090210 2009-02-10 3.21 -
ViRobot 20090209 2009.02.09 2009-02-09 0.40 -
Ikarus T3.1.01.45 2009.02.10.72283 2009-02-10 3.80 -
JiangMin 11.0.706 2009.02.10 2009-02-10 1.50 -
Kaspersky 5.5.10 2009.02.10 2009-02-10 0.04 -
KingSoft 2008.9.8.18 2009.2.10.22 2009-02-10 0.66 -
McAfee 5.3.00 5521 2009-02-09 3.19 -
Microsoft 1.4306 2009.02.10 2009-02-10 4.46 -
mks_vir 2.01 2009.02.09 2009-02-09 3.13 -
Norman 6.00.02 6.00.00 2009-02-09 8.01 -
Panda 9.05.01 2009.02.09 2009-02-09 1.62 -
Trend Micro 8.700-1004 5.829.00 2009-02-10 0.05 -
Quick Heal 10.00 2009.02.10 2009-02-10 1.64 -
Rising 20.0 21.16.12.00 2009-02-10 0.90 -
Sophos 2.83.3 4.38 2009-02-11 2.35 -
Sunbelt 4804 4804 2009-02-06 0.60 -
Symantec 1.3.0.24 20090210.003 2009-02-10 0.23 -
nProtect 20090210.07 3118216 2009-02-10 4.29 -
The Hacker 6.3.1.5 v00250 2009-02-09 0.53 -
VBA32 3.12.8.12 20090210.0906 2009-02-10 1.82 -
VirusBuster 4.5.11.10 10.101.8/894840 2009-02-10 1.88 -




Note: No Kaspersky Log beacuse no threats were detected


Thank You andrewuk for all your help, but now I think it is just a video card issue, but would like some help fixing it if possible :)
  • 0

#9
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Hello Jason1230

i am assuming you have uninstalled the superantispyware program you downloaded (i can see one on your machine)?

i would agree, it looks more hardware related. we have found no sign of any malware here.

i would not know how to help you (my best guess would be to update the drivers), but go to this part of the forum http://www.geekstogo...pherals-f9.html and post your issue - they will be able to help you.

say your machine has been checked and is clean of malware, and give the full description of the problem you gave me in the above post.



but before that, we will clear away the fix tools (this is so that should you ever be re-infected, you will download updated versions and it will also remove the quarantined Malware from your computer), reset your restore points (there will be infections lurking in there) and i will leave you with some ideas on how to enhance the protection of your machine against future infection.

====STEP 1====
Follow these steps to uninstall Combofix, the tools used in the removal of malware and to flush your system restore points
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    Posted Image
you can remove malwarebytes via the add/remove programs in your control panel


====STEP 2====
Please download the OTCleanIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTCleanIT.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Click on the CleanUp! button to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
you can also clear away any other tools we used.


====IDEAS TO SPEED UP YOUR MACHINE====
this page http://users.telenet...owcomputer.html gives some good ideas on how to improve the efficiency of your machine and has one or two useful links to help you further.


====AND FINALLY====
The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
  • Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
  • AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
  • SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
  • SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
  • IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
  • Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein

best wishes

andrewuk

Edited by andrewuk, 10 February 2009 - 04:58 PM.

  • 0

#10
andrewuk

andrewuk

    Trusted Helper

  • Malware Removal
  • 5,297 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP