Hi, I have an external drive that's plugged in, but the power is off. Would you like me to unplug it or turn it on in case the malware is there? I also have a USB key with some files, but not plugged in.
Here is the CF log:
ComboFix 08-04-07.5 - Jenny Zhao 2008-04-09 18:55:20.12 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.571 [GMT -4:00]
Running from: C:\Documents and Settings\Jenny Zhao\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jenny Zhao\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMbbac1797.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bckgegsf.dll
C:\WINDOWS\system32\jkkLFXno.dll
C:\WINDOWS\system32\khfEVMFX.dll
C:\WINDOWS\system32\NVGPqqss.ini
C:\WINDOWS\system32\NVGPqqss.ini2
C:\WINDOWS\system32\qqjlvygc.dll
C:\WINDOWS\system32\ssqqPGVN.dll
C:\WINDOWS\system32\vatboehv.dll
C:\WINDOWS\system32\vheobtav.ini
.
((((((((((((((((((((((((( Files Created from 2008-03-09 to 2008-04-09 )))))))))))))))))))))))))))))))
.
2008-04-09 18:59 . 2008-04-09 18:59 38,912 --a------ C:\WINDOWS\system32\geBuTkhe.dll
2008-04-09 14:57 . 2008-04-09 14:57 3,648 --a------ C:\WINDOWS\system32\gsrgpjjq.dll
2008-04-08 18:01 . 2008-04-08 18:21 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-04-07 20:33 . 2008-04-07 20:33 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-04-07 09:07 . 2008-04-07 09:07 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-06 18:19 . 2008-04-06 18:19 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-06 18:01 . 2008-04-06 18:01 <DIR> d-------- C:\WINDOWS\system32\regdacl
2008-04-06 18:01 . 2008-04-06 20:40 90,112 --a------ C:\WINDOWS\system32\regdacl.exe
2008-04-06 18:01 . 2008-04-06 20:40 53,248 --a------ C:\WINDOWS\system32\process.exe
2008-04-06 18:01 . 2008-04-06 20:40 16,384 --a------ C:\WINDOWS\system32\restart.exe
2008-04-06 18:01 . 2008-04-06 20:40 4,096 --a------ C:\WINDOWS\system32\reboot.exe
2008-04-06 10:55 . 2008-04-06 10:55 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-06 10:55 . 2008-04-06 10:55 <DIR> d-------- C:\Documents and Settings\Jenny Zhao\Application Data\Malwarebytes
2008-04-06 10:55 . 2008-04-06 10:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-06 08:34 . 2008-04-08 19:54 250 --a------ C:\WINDOWS\gmer.ini
2008-04-06 08:20 . 2008-04-06 08:20 <DIR> d-------- C:\Deckard
2008-04-05 18:04 . 2008-04-05 18:38 <DIR> d-------- C:\Documents and Settings\Jenny Zhao\DoctorWeb
2008-04-04 19:41 . 2008-04-04 19:41 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-04 19:41 . 2008-04-04 19:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-02 23:32 . 2008-04-02 23:33 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-04-02 19:02 . 2008-04-02 19:02 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-02 18:39 . 2008-04-02 18:46 <DIR> d-------- C:\Program Files\Panda Security
2008-04-02 18:39 . 2008-04-02 18:44 1,859 --a------ C:\WINDOWS\mozver.dat
2008-04-02 17:38 . 2008-04-02 19:24 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-02 17:38 . 2008-04-02 17:38 <DIR> d-------- C:\Documents and Settings\Jenny Zhao\Application Data\SUPERAntiSpyware.com
2008-04-02 17:38 . 2008-04-02 17:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-02 17:04 . 2008-04-02 17:04 <DIR> d-------- C:\Documents and Settings\Jenny Zhao\Application Data\Grisoft
2008-04-02 17:04 . 2008-04-02 17:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-02 17:04 . 2007-05-30 08:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-02 06:31 . 2008-04-02 21:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-02 06:30 . 2008-04-06 08:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-31 23:37 . 2008-04-01 16:15 <DIR> d-------- C:\Documents and Settings\Jenny Zhao\Contacts
2008-03-31 23:35 . 2008-03-31 23:35 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-31 23:34 . 2008-03-31 23:36 <DIR> d-------- C:\Program Files\Windows Live
2008-03-31 23:34 . 2008-03-31 23:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-31 19:57 . 2008-03-31 19:57 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-31 19:56 . 2008-03-31 19:56 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2008-03-31 19:55 . 2008-03-31 19:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-03-31 19:54 . 2008-03-31 19:57 <DIR> d-------- C:\WinFast WorkArea
2008-03-31 19:54 . 2008-03-31 19:56 <DIR> d-------- C:\WFDB
2008-03-31 19:54 . 2008-03-31 19:54 <DIR> d-------- C:\Program Files\WinFast
2008-03-31 19:54 . 2007-02-26 20:20 49,152 --a------ C:\WINDOWS\system32\TempDel.EXE
2008-03-31 19:54 . 2005-01-06 16:55 9,446 --a------ C:\WINDOWS\system32\drivers\WFIOCTL.sys
2008-03-31 19:46 . 2006-04-20 14:50 59,776 --a------ C:\WINDOWS\system32\drivers\wf2kvcap.sys
2008-03-31 19:46 . 2006-04-20 15:20 19,456 --a------ C:\WINDOWS\system32\drivers\wf2ktunr.sys
2008-03-31 19:46 . 2006-04-20 14:49 9,600 --a------ C:\WINDOWS\system32\drivers\wf2kXbar.sys
2008-03-31 19:34 . 2006-10-26 19:58 30,512 --a------ C:\WINDOWS\system32\mdimon.dll
2008-03-31 19:32 . 2008-03-31 19:32 <DIR> d-------- C:\Program Files\Microsoft Works
2008-03-31 19:28 . 2008-03-31 19:29 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-03-31 19:27 . 2008-03-31 19:27 <DIR> dr-h----- C:\MSOCache
2008-03-31 19:27 . 2008-04-02 20:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-31 17:53 . 2008-03-31 18:53 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-03-31 17:53 . 2006-09-06 18:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-31 17:46 . 2007-07-30 20:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-03-31 17:46 . 2007-07-30 20:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-03-31 17:46 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-03-31 17:46 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-03-31 17:46 . 2007-07-30 20:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-03-31 17:45 . 2008-03-31 17:45 <DIR> d--hs---- C:\Documents and Settings\Jenny Zhao\UserData
2008-03-31 17:44 . 2008-03-31 17:44 0 --a------ C:\WINDOWS\vpc32.INI
2008-03-31 17:32 . 2008-04-09 18:59 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2008-03-31 17:32 . 2008-03-31 17:32 <DIR> d-------- C:\Program Files\Symantec
2008-03-31 17:32 . 2008-03-31 17:32 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-31 17:32 . 2008-03-31 17:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-31 17:32 . 2006-09-18 18:55 109,744 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-31 17:32 . 2006-09-18 18:55 48,816 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-03-31 13:00 . 2004-08-03 20:56 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll
2008-03-31 13:00 . 2004-08-03 18:29 1,897,408 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-03-31 13:00 . 2004-08-04 01:56 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2008-03-31 13:00 . 2004-08-04 01:56 74,240 --a--c--- C:\WINDOWS\system32\dllcache\usbui.dll
2008-03-31 13:00 . 2004-08-03 18:59 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-03-31 13:00 . 2004-08-04 00:07 42,368 --a------ C:\WINDOWS\system32\drivers\AGP440.SYS
2008-03-31 13:00 . 2004-08-04 00:07 42,368 --a--c--- C:\WINDOWS\system32\dllcache\agp440.sys
2008-03-31 13:00 . 2004-08-03 18:59 5,504 --a------ C:\WINDOWS\system32\drivers\intelide.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-31 23:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-31 23:54 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-31 23:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logishrd
2008-03-31 23:01 --------- d-----w C:\Program Files\Common Files\LogiShrd
2008-03-31 22:58 --------- d-----w C:\Program Files\Logitech
2008-03-31 22:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logitech
2008-03-31 22:22 --------- d-----w C:\Program Files\Analog Devices
2008-03-31 22:20 --------- d-----w C:\Program Files\Intel
2008-03-31 22:07 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-09 19:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
.
((((((((((((((((((((((((((((( snapshot@2008-04-08_10.49.47.76 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-08 22:03:06 45,056 ----a-w C:\WINDOWS\BDOSCAN8\avxdisk.dll
+ 2008-04-08 22:03:06 10,240 ----a-w C:\WINDOWS\BDOSCAN8\avxs.dll
+ 2008-04-08 22:03:06 27,136 ----a-w C:\WINDOWS\BDOSCAN8\avxt.dll
+ 2008-04-08 22:03:08 181,760 ----a-w C:\WINDOWS\BDOSCAN8\bdcore.dll
+ 2008-01-09 19:01:48 118,784 ----a-w C:\WINDOWS\BDOSCAN8\bdupd.dll
+ 2008-01-09 19:01:48 53,248 ----a-w C:\WINDOWS\BDOSCAN8\ipsupd.dll
+ 2008-04-08 22:03:09 142,848 ----a-w C:\WINDOWS\BDOSCAN8\libfn.dll
+ 2008-04-08 22:03:07 86,016 ----a-w C:\WINDOWS\BDOSCAN8\librtvr.dll
+ 2008-01-09 19:01:48 118,784 ----a-w C:\WINDOWS\Downloaded Program Files\bdupd.dll
+ 2008-01-09 19:01:48 53,248 ----a-w C:\WINDOWS\Downloaded Program Files\ipsupd.dll
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Avenger\advusbpa.dll
2008-04-08 19:41 91712 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014934.dll
C:\Avenger\backup.reg
2008-04-06 11:39 3419 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0008084.reg
2008-04-09 16:51 2752 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014974.reg
C:\Avenger\bknjsmfp.dll
2008-04-08 17:51 83520 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014884.dll
C:\Avenger\byXOggGw.dll
2008-04-09 14:49 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014961.dll
C:\Avenger\byXQJAro.dll
2008-04-06 21:14 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013408.dll
C:\Avenger\fccbCutu.dll
2008-04-06 20:25 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013366.dll
2008-04-06 21:13 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013409.dll
C:\Avenger\gwwxurmx.dll
2008-04-08 10:59 3648 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014885.dll
C:\Avenger\hgGywVMG.dll
2008-04-09 14:35 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014962.dll
C:\Avenger\hjoydfiq.dll
2008-04-08 17:49 88640 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014886.dll
C:\Avenger\iiffCTKD.dll
2008-04-06 20:09 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013367.dll
2008-04-06 21:13 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013410.dll
C:\Avenger\jkkJbcBs.dll
2008-04-06 20:42 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013368.dll
2008-04-06 21:13 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013411.dll
C:\Avenger\jkkLFxvT.dll
2008-04-06 20:07 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013369.dll
2008-04-06 21:13 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013412.dll
C:\Avenger\lgmpoipb.dll
2008-04-08 19:30 88640 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014937.dll
C:\Avenger\mlJBUNET.dll
2008-04-08 19:29 269824 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014938.dll
C:\Avenger\qvajcqgi.dll
2008-04-08 19:32 3648 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014941.dll
C:\Avenger\rlkwsiyh.dll
2008-04-08 19:38 83520 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014942.dll
C:\Avenger\rqRJDstQ.dll
2008-04-08 17:41 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014887.dll
C:\Avenger\rqRKcyyy.dll
2008-04-08 19:24 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014943.dll
C:\Avenger\rqRLbxUn.dll
2008-04-06 19:59 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013370.dll
2008-04-06 21:13 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013413.dll
C:\Avenger\tuvTmNHb.dll
2008-04-06 18:36 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013371.dll
2008-04-06 21:13 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013414.dll
C:\Avenger\urqOGXqR.dll
2008-04-08 17:48 269824 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014888.dll
C:\Avenger\vebwsuan.dll
2008-04-08 11:29 3648 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014946.dll
C:\Avenger\vxpclcwk.dll
2008-04-08 17:51 3648 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014947.dll
C:\Avenger\wegjosbd.dll
2008-04-08 17:54 91712 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014948.dll
C:\Avenger\xxyAtULD.dll
2008-04-06 19:26 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013372.dll
2008-04-06 21:13 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013415.dll
C:\Avenger\yayaXoMg.dll
2008-04-08 17:44 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014949.dll
C:\cleanup.bat
2008-04-06 11:39 574 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0008087.bat
2008-04-09 16:51 574 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014977.bat
C:\cleanup.exe
2008-04-06 11:39 19286 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0008086.exe
2008-04-09 16:51 19286 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014976.exe
2006-12-06 09:06 4096 C:\Documents and Settings\All Users\Application Data\Grisoft\AVG Anti-Spyware 7.5\Downloads\help.dll
2006-12-06 09:06 4096 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP36\A0006820.dll
2006-12-06 09:06 4096 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP53\A0015010.dll
C:\Documents and Settings\Jenny Zhao\Application Data\Microsoft\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
2008-04-02 23:06 1038336 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007056.exe
C:\Documents and Settings\Jenny Zhao\Application Data\Microsoft\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
2008-04-02 23:06 178688 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007057.exe
2008-03-03 12:19 731136 C:\Documents and Settings\Jenny Zhao\Desktop\avenger\avenger.exe
2008-03-03 12:19 731136 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013401.exe
2008-03-03 12:19 731136 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014928.exe
C:\Documents and Settings\Jenny Zhao\Desktop\OTScanIt\OTScanIt\MovedFiles\
04072008_105658\WINDOWS\system32\fmybdslr.dll
2008-04-07 08:15 88128 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP50\A0013851.dll
C:\Documents and Settings\Jenny Zhao\Desktop\OTScanIt\OTScanIt\MovedFiles\
04072008_105658\WINDOWS\system32\xkpepeaw.dll
2008-04-07 08:21 85056 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP50\A0013849.dll
C:\Documents and Settings\Jenny Zhao\Desktop\OTScanIt\OTScanIt\MovedFiles\
04072008_105658\WINDOWS\system32\ycgovuwc.dll
2008-04-07 08:18 90176 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP50\A0013850.dll
C:\Documents and Settings\Jenny Zhao\Desktop\OTScanIt\OTScanIt\MovedFiles\
04072008_105658\WINDOWS\Temp\removalfile.bat
2008-04-07 09:17 43 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP50\A0013853.bat
C:\Documents and Settings\Jenny Zhao\Desktop\OTScanIt\OTScanIt\MovedFiles\
04072008_110757\WINDOWS\Temp\removalfile.bat
2008-04-07 10:59 43 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP50\A0013854.bat
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\attrib.exe
2001-08-23 08:00 11264 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013482.exe
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\AppInit_DLLs.reg
2008-04-07 09:07 624 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013451.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\bat_shell_open.reg
2008-04-07 09:07 204 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013452.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\BHO.reg
2008-04-07 09:07 2288 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013453.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\com_shell_open.reg
2008-04-07 09:07 204 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013454.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\ControlPanel_Load.reg
2008-04-07 09:07 22476 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013455.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\Drivers32.reg
2008-04-07 09:07 3066 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013456.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\exe_shell_open.reg
2008-04-07 09:07 204 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013457.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\HKCU_SOFTWARE_Policy.reg
2008-04-07 09:07 3810 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013460.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\HKCU_WINDOWS_Policy.reg
2008-04-07 09:07 1704 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013461.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\HKCURun.reg
2008-04-07 09:07 482 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013458.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\HKCURunServices.reg
2008-04-07 09:07 228 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013459.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\HKLM_SOFTWARE_Policy.reg
2008-04-07 09:07 118942 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013464.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\HKLM_WINDOWS_Policy.reg
2008-04-07 09:07 2782 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013465.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\HKLMRun.reg
2008-04-07 09:07 2738 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013462.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\HKLMRunServices.reg
2008-04-07 09:07 230 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013463.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\hta_shell_open.reg
2008-04-07 09:07 270 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013466.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\IEDesktop.reg
2008-04-07 09:07 4748 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013467.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\IEMain.reg
2008-04-07 09:07 4352 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013468.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\Installed_Components.reg
2008-04-07 09:07 26492 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013469.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\pif_shell_open.reg
2008-04-07 09:07 204 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013470.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\reg_shell_open.reg
2008-04-07 09:07 228 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013471.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\SecurityProviders.reg
2008-04-07 09:07 8004 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013472.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\SharedTaskScheduler.reg
2008-04-07 09:07 546 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013473.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\ShellServiceObjectDelayLoad.reg
2008-04-07 09:07 696 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013474.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\SubSystems.reg
2008-04-07 09:07 5282 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013475.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\txt_shell_open.reg
2008-04-07 09:07 668 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013476.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\Winlogon.reg
2008-04-07 09:07 30268 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013477.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backupreg\WinlogonNotify.reg
2008-04-07 09:07 13618 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013478.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\byXQJAro.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013441.dll
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\fccbCutu.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013442.dll
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\iiffCTKD.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013443.dll
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\jkkJbcBs.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013444.dll
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\jkkLFxvT.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013445.dll
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\removalfile.bat
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013446.bat
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\rqRLbxUn.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013447.dll
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\tuvTmNHb.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013448.dll
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\userinit.reg
2008-04-07 09:08 141 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013449.reg
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\backups\xxyAtULD.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013450.dll
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\dummy.exe
2008-04-07 12:18 6656 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013479.exe
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\find.exe
2001-08-23 08:00 9216 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013480.exe
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\findstr.exe
2004-08-04 00:56 27136 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013481.exe
C:\Documents and Settings\Jenny Zhao\Desktop\SDFix\SDFix\regedit.exe
2004-08-04 00:56 146432 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013483.exe
C:\EECTRL.SYS
2008-03-18 16:13 385072 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014913.SYS
C:\NAVENG.SYS
2008-03-18 16:13 82256 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014916.SYS
2008-03-18 16:13 109616 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
2008-03-18 16:13 109616 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007071.sys
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080404.003\CCERASER.DLL
2008-03-18 16:13 2561072 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013382.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080404.003\ECMSVR32.DLL
2008-03-18 16:13 284016 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013384.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080404.003\EECTRL.SYS
2008-03-18 16:13 385072 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013385.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080404.003\ERASER.SYS
2008-03-18 16:13 109616 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013387.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080404.003\NAVENG.SYS
2008-03-18 16:13 82256 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013388.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080404.003\NAVENG32.DLL
2008-03-18 16:13 128368 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013390.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080404.003\NAVEX15.SYS
2008-03-18 16:13 895408 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013391.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080404.003\NAVEX32A.DLL
2008-03-18 16:13 943472 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013393.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080405.003\CCERASER.DLL
2008-03-18 16:13 2561072 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP46\A0013582.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080405.003\ECMSVR32.DLL
2008-03-18 16:13 284016 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP46\A0013584.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080405.003\EECTRL.SYS
2008-03-18 16:13 385072 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP46\A0013585.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080405.003\ERASER.SYS
2008-03-18 16:13 109616 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP46\A0013587.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080405.003\NAVENG.SYS
2008-03-18 16:13 82256 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP46\A0013588.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080405.003\NAVENG32.DLL
2008-03-18 16:13 128368 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP46\A0013590.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080405.003\NAVEX15.SYS
2008-03-18 16:13 895408 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP46\A0013591.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080405.003\NAVEX32A.DLL
2008-03-18 16:13 943472 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP46\A0013593.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080406.003\CCERASER.DLL
2008-03-18 16:13 2561072 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014910.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080406.003\ECMSVR32.DLL
2008-03-18 16:13 284016 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014912.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080406.003\EECTRL.SYS
2008-03-18 16:13 385072 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014913.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080406.003\ERASER.SYS
2008-03-18 16:13 109616 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014915.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080406.003\NAVENG.SYS
2008-03-18 16:13 82256 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014916.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080406.003\NAVENG32.DLL
2008-03-18 16:13 128368 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014918.DLL
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080406.003\NAVEX15.SYS
2008-03-18 16:13 895408 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014919.SYS
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080406.003\NAVEX32A.DLL
2008-03-18 16:13 943472 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014921.DLL
C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP\WiseCustCall64.dll
2008-04-06 08:00 37376 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007050.dll
C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP\WiseCustomCall.dll
2008-04-06 08:00 22195 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007051.dll
C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP\WiseCustomCalla.dll
2008-04-06 08:00 73728 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007052.dll
2008-03-03 20:29 761856 C:\WINDOWS\gmer.exe
2008-03-03 20:29 761856 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0011295.exe
2008-03-03 20:29 761856 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014899.exe
C:\WINDOWS\system32\ajjvymmn.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP43\A0008112.dll
C:\WINDOWS\system32\awtsRlLD.dll
2008-04-05 17:59 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP38\A0006887.dll
C:\WINDOWS\system32\bckgegsf.dll
2008-04-09 14:54 89664 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP53\A0014989.dll
C:\WINDOWS\system32\bddnsens.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP38\A0006873.dll
C:\WINDOWS\system32\bmcjjfgw.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP49\A0013787.dll
C:\WINDOWS\system32\byXPGVpP.dll
2008-04-06 19:04 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0012298.dll
C:\WINDOWS\system32\byXQJAro.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013429.dll
C:\WINDOWS\system32\ddcAtuTL.dll
2008-04-07 11:09 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013673.dll
C:\WINDOWS\system32\ddcCrpOH.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP38\A0006874.dll
C:\WINDOWS\system32\ddcyvSMf.dll
2008-04-04 19:08 269312 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP36\A0006812.dll
C:\WINDOWS\system32\dfcndxig.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0012288.dll
C:\WINDOWS\system32\drivers\advts.sys
2008-04-09 16:44 61440 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014955.sys
C:\WINDOWS\system32\drivers\bozwnh.sys
2008-04-07 08:34 61440 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013403.sys
C:\WINDOWS\system32\drivers\goclkhbm.sys
2008-04-08 19:22 61440 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014879.sys
C:\WINDOWS\system32\drivers\kpje.sys
2008-04-09 16:51 61440 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014969.sys
C:\WINDOWS\system32\drivers\lhwzc.sys
2008-04-06 11:39 61440 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0008080.sys
C:\WINDOWS\system32\drivers\ubwt.sys
2008-04-06 21:12 61440 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013361.sys
C:\WINDOWS\system32\drivers\vdi2mzq2.sys
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007059.sys
C:\WINDOWS\system32\drivers\yzxiiv.sys
2008-04-09 14:46 61440 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014930.sys
C:\WINDOWS\system32\efcDWOEU.dll
2008-04-04 21:23 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP36\A0006795.dll
C:\WINDOWS\system32\epnbplqj.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0012302.dll
C:\WINDOWS\system32\fccbCutu.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013430.dll
C:\WINDOWS\system32\fkqycafn.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP43\A0008113.dll
C:\WINDOWS\system32\hgGxULfe.dll
2008-04-05 19:29 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP40\A0006953.dll
C:\WINDOWS\system32\hlukrhgj.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP38\A0006875.dll
C:\WINDOWS\system32\hwwrjskk.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP40\A0006941.dll
C:\WINDOWS\system32\hylhhekb.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007060.dll
C:\WINDOWS\system32\igcwvpbu.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP40\A0006942.dll
C:\WINDOWS\system32\iifcBtRk.dll
2008-04-06 07:36 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007077.dll
C:\WINDOWS\system32\iiffCRkJ.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP49\A0013788.dll
C:\WINDOWS\system32\iiffCTKD.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013431.dll
C:\WINDOWS\system32\iykxsash.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP36\A0006796.dll
C:\WINDOWS\system32\jkkJbcBs.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013432.dll
C:\WINDOWS\system32\jkkLBrQj.dll
2008-04-05 19:31 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007061.dll
C:\WINDOWS\system32\jkkLFXno.dll
2008-04-09 16:46 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP53\A0015002.dll
C:\WINDOWS\system32\jkkLFxvT.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013433.dll
C:\WINDOWS\system32\jmefkjto.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007074.dll
C:\WINDOWS\system32\jmilinxq.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007062.dll
C:\WINDOWS\system32\jxfuyvrr.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007063.dll
C:\WINDOWS\system32\khfEVMFX.dll
2008-04-09 16:53 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP53\A0014990.dll
C:\WINDOWS\system32\khfGvsqp.dll
2008-04-06 19:34 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013329.dll
C:\WINDOWS\system32\knewlysr.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013674.dll
C:\WINDOWS\system32\ktpobcsq.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013675.dll
C:\WINDOWS\system32\kvpdsmyb.dll
2008-04-06 11:17 85056 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0008078.dll
C:\WINDOWS\system32\kyhqpyjp.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP49\A0013789.dll
C:\WINDOWS\system32\lahofkve.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP40\A0006943.dll
C:\WINDOWS\system32\lcbmxxkn.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013676.dll
C:\WINDOWS\system32\ljJARiJc.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0011288.dll
C:\WINDOWS\system32\lpeayooo.dll
2008-04-08 11:27 88640 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP50\A0014859.dll
C:\WINDOWS\system32\mlJYrono.dll
2008-04-05 11:56 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP36\A0006797.dll
C:\WINDOWS\system32\MRT.exe
2008-03-05 09:30 19148408 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP48\A0013777.exe
C:\WINDOWS\system32\nnnllKAr.dll
2008-04-07 20:18 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013677.dll
C:\WINDOWS\system32\nnnnLcyX.dll
2008-04-04 19:03 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP36\A0006813.dll
C:\WINDOWS\system32\nnnnLdAP.dll
2008-04-06 15:40 268288 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP44\A0011233.dll
C:\WINDOWS\system32\opnnonLD.dll
2008-04-06 17:34 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0011245.dll
C:\WINDOWS\system32\opnommlk.dll
2008-04-05 20:42 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007078.dll
C:\WINDOWS\system32\pbrjaetc.dll
2008-04-06 11:17 87104 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0008093.dll
C:\WINDOWS\system32\pmnljKbX.dll
2008-04-06 07:21 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007064.dll
C:\WINDOWS\system32\pmnnLBqn.dll
2008-04-05 16:53 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP38\A0006876.dll
2008-04-06 20:40 53248 C:\WINDOWS\system32\process.exe
2008-04-06 18:01 53248 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0011258.exe
2008-04-06 20:23 53248 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013353.exe
C:\WINDOWS\system32\pyegtnmd.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013678.dll
C:\WINDOWS\system32\qfwjhygg.dll
2008-04-06 15:40 85056 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP44\A0011237.dll
C:\WINDOWS\system32\qqjlvygc.dll
2008-04-09 15:03 95808 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP53\A0014991.dll
C:\WINDOWS\system32\rdwmwoku.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013342.dll
2008-04-06 20:40 4096 C:\WINDOWS\system32\reboot.exe
2008-04-06 18:01 4096 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0011255.exe
2008-04-06 20:23 4096 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013350.exe
2008-04-06 20:40 90112 C:\WINDOWS\system32\regdacl.exe
2008-04-06 18:01 90112 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0011254.exe
2008-04-06 20:23 90112 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013349.exe
2008-04-06 20:40 4175 C:\WINDOWS\system32\regdacl\doc\SMWNCV.cmd
2008-04-06 18:01 4175 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0011253.cmd
2008-04-06 20:23 4175 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013348.cmd
2008-04-06 20:40 16384 C:\WINDOWS\system32\restart.exe
2008-04-06 18:01 16384 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0011257.exe
2008-04-06 20:23 16384 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013352.exe
C:\WINDOWS\system32\rqRHaXOE.dll
2008-04-07 08:36 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013693.dll
C:\WINDOWS\system32\rqRHbBTk.dll
2008-04-08 11:26 269824 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP50\A0014860.dll
C:\WINDOWS\system32\rqRHxuvS.dll
2008-04-06 14:24 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP43\A0008187.dll
C:\WINDOWS\system32\rqRJAqPI.dll
2008-04-08 09:11 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013679.dll
C:\WINDOWS\system32\rqRKDWqo.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP40\A0006944.dll
C:\WINDOWS\system32\rqRLbcBs.dll
2008-04-06 15:40 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP44\A0011239.dll
C:\WINDOWS\system32\rqRLbxUn.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013434.dll
C:\WINDOWS\system32\rqRLeeBQ.dll
2008-04-07 10:59 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013680.dll
C:\WINDOWS\system32\rqRLfcaB.dll
2008-04-07 08:14 267776 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013694.dll
C:\WINDOWS\system32\rtqojtph.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013355.dll
C:\WINDOWS\system32\sbmajava.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013681.dll
C:\WINDOWS\system32\seprddxt.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP36\A0006798.dll
C:\WINDOWS\system32\spxysetk.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0012301.dll
C:\WINDOWS\system32\ssqOIAsT.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007073.dll
C:\WINDOWS\system32\ssqPifcC.dll
2008-04-08 11:20 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP50\A0014861.dll
C:\WINDOWS\system32\ssqqPGVN.dll
2008-04-09 14:54 270336 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP53\A0015003.dll
C:\WINDOWS\system32\ssqRKede.dll
2008-04-06 08:10 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007076.dll
C:\WINDOWS\system32\taymlamm.dll
2008-04-08 11:32 83520 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP50\A0014858.dll
C:\WINDOWS\system32\tuvSIbXq.dll
2008-04-06 18:03 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0012300.dll
C:\WINDOWS\system32\tuvTmNHb.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013435.dll
C:\WINDOWS\system32\uegrsndm.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP49\A0013790.dll
C:\WINDOWS\system32\ugnrkwjs.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP38\A0006877.dll
C:\WINDOWS\system32\uhevhedr.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP43\A0008111.dll
C:\WINDOWS\system32\ulecybox.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP47\A0013682.dll
C:\WINDOWS\system32\urqPhgfd.dll
2008-04-06 11:17 268288 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0008089.dll
C:\WINDOWS\system32\urqRhHxx.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007065.dll
C:\WINDOWS\system32\uvutasfw.dll
2008-04-06 15:40 87104 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP44\A0011240.dll
C:\WINDOWS\system32\vatboehv.dll
2008-04-09 15:06 84544 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP53\A0014992.dll
C:\WINDOWS\system32\vtUlIyWQ.dll
2008-04-06 14:22 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP43\A0008127.dll
C:\WINDOWS\system32\vtUlIyyA.dll
2008-04-06 18:18 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0012299.dll
C:\WINDOWS\system32\wixkdkcv.dll
2008-04-06 11:17 85056 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0008091.dll
C:\WINDOWS\system32\wvUMGvSm.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013316.dll
C:\WINDOWS\system32\xcnfubbo.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013302.dll
C:\WINDOWS\system32\xdebcngd.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0007075.dll
C:\WINDOWS\system32\xxyAtULD.dll
2008-04-07 08:35 0 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP45\A0013436.dll
C:\WINDOWS\system32\xxyvusRH.dll
2008-04-06 13:29 268288 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP43\A0008128.dll
C:\WINDOWS\system32\xxyxYsSK.dll
2008-04-08 11:18 38912 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP49\A0013800.dll
C:\WINDOWS\system32\yarputtw.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP36\A0006799.dll
C:\WINDOWS\system32\ykuidpyg.dll
{FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP43\A0008114.dll
C:\zip.exe
2008-04-06 11:39 135168 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP42\A0008085.exe
2008-04-09 16:51 135168 {FC28582C-DBF4-4B0E-BC7E-F7504CB5F12E}\RP51\A0014975.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\Smtray.exe" [2002-03-19 12:01 90112]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 20:26 52896]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 21:33 125168]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"WinFast Schedule"="C:\Program Files\WinFast\WFTVFM\WFWIZ.exe" [2007-10-18 13:47 876544]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BFA7416F-6EBA-43E5-B485-D32C6C78E1DB}"= C:\WINDOWS\system32\geBuTkhe.dll [2008-04-09 18:59 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-04-02 19:24 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geBuTkhe]
geBuTkhe.dll 2008-04-09 18:59 38912 C:\WINDOWS\system32\geBuTkhe.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkLFXno]
jkkLFXno.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\drivers\si3112r.sys [2002-08-29 07:52]
R2 BT848;WinFast TV2000 XP WDM Video Capture;C:\WINDOWS\system32\drivers\wf2kvcap.sys [2006-04-20 14:50]
R2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;C:\WINDOWS\system32\drivers\wf2ktunr.sys [2006-04-20 15:20]
R2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;C:\WINDOWS\system32\drivers\wf2kxbar.sys [2006-04-20 14:49]
R3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS [2005-01-06 16:55]
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-09 18:59:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\geBuTkhe.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2008-04-09 19:00:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-09 23:00:41
ComboFix2.txt 2008-04-08 15:21:35
ComboFix3.txt 2008-04-08 14:50:18
ComboFix4.txt 2008-04-06 18:38:10
Pre-Run: 115,364,577,280 bytes free
Post-Run: 115,348,942,848 bytes free
Here is the DSS log:
Deckard's System Scanner v20071014.68
Run by Jenny Zhao on 2008-04-09 19:01:40
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Jenny Zhao.exe) ------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:01:42 PM, on 4/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Jenny Zhao\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\JENNYZ~1.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra bu