Re: FB virus asi...Pomoc
Napsal: 22 lis 2010 18:44
zdravim vsetko bolo ok...ale moja sestra zas klikla na ten link vtedy som to bol ja ::/ zabudol som jej o tom povedat na FB chate a mam tiez problemy znova pridavam log z RSIT
Logfile of random's system information tool 1.08 (written by random/random)
Run by Hong at 2010-11-22 18:44:30
Microsoft Windows XP Professional Service Pack 3
System drive C: has 45 GB (46%) free of 98 GB
Total RAM: 2559 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:44:36, on 22.11.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\loosoujouzous.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Hong\Desktop\RSIT.exe
C:\Program Files\trend micro\Hong.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fullarticles.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.games-fusion.net
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mupoga] C:\WINDOWS\system32\loosoujouzous.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: 0o65u1l.exe
O4 - Startup: 0ttzpgw.exe
O4 - Startup: 0x0nt20.exe
O4 - Startup: 5nyj26a.exe
O4 - Startup: 69o1pvg.exe
O4 - Startup: bwsidte0k6.exe
O4 - Startup: c8tzpgwr.exe
O4 - Startup: cc8tzpgwr26.exe
O4 - Startup: ffwrrns7.exe
O4 - Startup: hsydup6a0h.exe
O4 - Startup: ie0aa5b0.exe
O4 - Startup: iy0uk0vgw0.exe
O4 - Startup: lh5syz2k1.exe
O4 - Startup: qb271z2k1g.exe
O4 - Startup: r60ttzpgw.exe
O4 - Startup: rc3oo3avbm0.exe
O4 - Startup: rw3ii3uu.exe
O4 - Startup: rxc3oo3avbm.exe
O4 - Startup: xidzzvlr.exe
O4 - Startup: xy0o3avb.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} - http://go.microsoft.com/fwlink/?linkid=39204
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: PowerUtility TV Recording Reservation (u1thmtecye6) - Unknown owner - C:\WINDOWS\system32\pyhu.exe
--
End of file - 4812 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-FAJKOS-Hong.job
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1275498585.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-839522115-1617979688-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-839522115-1617979688-1003UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"NVMixerTray"=C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe [2004-06-03 131072]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-07-07 1753192]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-07-09 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-07-09 13923432]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"mupoga"=C:\WINDOWS\system32\loosoujouzous.exe [2010-11-22 201216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
C:\Program Files\Cyberlink\Shared files\brs.exe [2010-06-28 75048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-04-12 1135912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Hong\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-24 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.1\ICQ.exe [2010-10-27 133432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-09-04 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2010-07-09 110696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
D:\PowerDVD10\PDVD10Serv.exe [2010-02-02 87336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-02-14 148888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2010-07-12 74752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe [2003-04-06 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^0ddzppl.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\0ddzppl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^5n0tup8.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\5n0tup8.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^a1wssneezq.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\a1wssneezq.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^a3mc1ijj.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\a3mc1ijj.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^Adobe Gamma.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^avbg3ss3.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\avbg3ss3.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^bhxnijjf.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\bhxnijjf.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^cxxotup83.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\cxxotup83.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^fagg3ss3ee1.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\fagg3ss3ee1.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^g70hdyy6k.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\g70hdyy6k.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^i3uuklq8.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\i3uuklq8.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^i3uuklq860.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\i3uuklq860.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^lwhns3ee1q.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\lwhns3ee1q.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^MagicDisc.lnk]
C:\PROGRA~1\MAGICD~1\MAGICD~1.EXE [2009-02-23 576000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^riddzpplq3.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\riddzpplq3.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^rrnddzpplbb.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\rrnddzpplbb.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^s86e81qbcxd.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\s86e81qbcxd.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^uk0g3ss3ee1.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\uk0g3ss3ee1.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^vmmhyytk.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\vmmhyytk.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^w0xnijjfk3.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\w0xnijjfk3.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^whx9ye0k3w.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\whx9ye0k3w.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^WinFlip.lnk]
C:\PROGRA~1\WinFlip\WinFlip.exe [2007-10-25 462848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^y8703g0hxd6.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\y8703g0hxd6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3
"idsvc"=3
"ICQ Service"=2
"WZCSVC"=2
"wuauserv"=2
"wscsvc"=2
"JavaQuickStarterService"=2
"NetTcpPortSharing"=2
"WMPNetworkSvc"=3
"gusvc"=2
"gupdate1c9aca3419ed106"=2
"Viewpoint Manager Service"=2
"MDM"=2
"Adobe LM Service"=3
"ServiceLayer"=3
"IDriverT"=3
"fsssvc"=3
"FLEXnet Licensing Service"=3
"nvsvc"=2
"nTuneService"=2
"CachemanXPService"=3
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Documents and Settings\Hong\Start Menu\Programs\Startup
0o65u1l.exe
0ttzpgw.exe
0x0nt20.exe
5nyj26a.exe
69o1pvg.exe
bwsidte0k6.exe
c8tzpgwr.exe
cc8tzpgwr26.exe
ffwrrns7.exe
hsydup6a0h.exe
ie0aa5b0.exe
iy0uk0vgw0.exe
lh5syz2k1.exe
qb271z2k1g.exe
r60ttzpgw.exe
rc3oo3avbm0.exe
rw3ii3uu.exe
rxc3oo3avbm.exe
xidzzvlr.exe
xy0o3avb.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
WgaLogon.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-19 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoSMBalloonTip"=0
"NoDesktopCleanupWizard"=1
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoResolveSearch"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
======List of files/folders created in the last 1 months======
2010-11-22 18:42:01 ----D---- C:\WINDOWS\temp
2010-11-22 18:41:59 ----A---- C:\ComboFix.txt
2010-11-22 15:56:40 ----A---- C:\WINDOWS\system32\pyhu.exe
2010-11-22 15:56:24 ----RA---- C:\Documents and Settings\Hong\Application Data\BG0Ai.txt
2010-11-22 15:56:23 ----A---- C:\WINDOWS\system32\loosoujouzous.exe
2010-11-21 18:50:36 ----D---- C:\Documents and Settings\Hong\Application Data\Mumble
2010-11-21 18:50:03 ----D---- C:\Program Files\Mumble
2010-11-20 22:17:16 ----D---- C:\Program Files\The KMPlayer
2010-11-16 19:48:08 ----A---- C:\WINDOWS\IE4 Error Log.txt
2010-11-15 22:58:12 ----D---- C:\Documents and Settings\Hong\Application Data\TS3Client
2010-11-15 22:57:55 ----D---- C:\Program Files\TeamSpeak 3 Client
2010-11-14 21:42:33 ----D---- C:\Config.Msi
2010-11-14 19:02:10 ----RASHD---- C:\cmdcons
2010-11-14 18:44:16 ----D---- C:\rsit
2010-11-14 18:23:48 ----A---- C:\WINDOWS\zip.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\SWSC.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\SWREG.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\sed.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\PEV.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\NIRCMD.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\MBR.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\grep.exe
2010-11-14 18:22:58 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-11-14 18:19:23 ----D---- C:\WINDOWS\ERDNT
2010-11-14 18:16:50 ----AD---- C:\Qoobox
2010-11-14 17:49:13 ----A---- C:\WINDOWS\ntbtlog.txt
2010-11-14 17:44:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-11-14 13:10:32 ----A---- C:\WINDOWS\wininit.ini
2010-11-13 19:36:38 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-11-13 19:36:38 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-10-28 22:42:20 ----D---- C:\Documents and Settings\All Users\Application Data\Trymedia
======List of files/folders modified in the last 1 months======
2010-11-22 18:44:32 ----D---- C:\Program Files\Trend Micro
2010-11-22 18:42:01 ----D---- C:\WINDOWS\system32\drivers
2010-11-22 18:42:01 ----D---- C:\WINDOWS
2010-11-22 18:40:05 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-22 18:37:39 ----A---- C:\WINDOWS\system.ini
2010-11-22 18:37:19 ----D---- C:\WINDOWS\system32\drivers\etc
2010-11-22 18:34:20 ----D---- C:\WINDOWS\system32
2010-11-22 18:34:20 ----D---- C:\WINDOWS\AppPatch
2010-11-22 18:34:19 ----D---- C:\Program Files\Common Files
2010-11-22 18:20:45 ----D---- C:\WINDOWS\system32\config
2010-11-22 18:01:07 ----D---- C:\WINDOWS\Prefetch
2010-11-22 15:20:21 ----D---- C:\Documents and Settings\Hong\Application Data\ICQ
2010-11-21 20:44:09 ----A---- C:\WINDOWS\win.ini
2010-11-21 18:50:03 ----RD---- C:\Program Files
2010-11-20 22:15:36 ----D---- C:\Documents and Settings\Hong\Application Data\vlc
2010-11-18 21:21:35 ----SD---- C:\WINDOWS\Tasks
2010-11-18 11:25:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-11-14 21:47:45 ----D---- C:\WINDOWS\pss
2010-11-14 21:42:39 ----SHD---- C:\WINDOWS\Installer
2010-11-14 21:42:28 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-11-14 19:02:16 ----RASH---- C:\boot.ini
2010-11-14 18:29:14 ----HD---- C:\WINDOWS\inf
2010-11-14 18:22:53 ----D---- C:\WINDOWS\WinSxS
2010-11-14 17:49:20 ----SHD---- C:\WINDOWS\CSC
2010-11-14 17:41:58 ----D---- C:\WINDOWS\system32\LogFiles
2010-11-14 17:30:46 ----D---- C:\WINDOWS\system32\appmgmt
2010-11-14 17:13:58 ----A---- C:\Boot.bak
2010-11-12 11:24:44 ----A---- C:\WINDOWS\NeroDigital.ini
2010-11-10 16:47:27 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-11-10 16:47:07 ----D---- C:\Program Files\Adobe
2010-11-10 16:46:56 ----D---- C:\Program Files\Common Files\Adobe
2010-11-03 16:24:36 ----D---- C:\Documents and Settings\Hong\Application Data\uTorrent
2010-11-03 14:34:41 ----D---- C:\Documents and Settings\All Users\Application Data\Blizzard Entertainment
2010-11-02 18:52:46 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2010-10-31 23:24:24 ----D---- C:\Program Files\ICQ7.1
2010-10-28 22:30:23 ----RSD---- C:\WINDOWS\assembly
2010-10-28 22:30:04 ----D---- C:\WINDOWS\system32\DirectX
2010-10-26 15:59:15 ----D---- C:\Documents and Settings\Hong\Application Data\SystemRequirementsLab
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-04-22 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2010-06-02 82380]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 36864]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/07/11 13:05:02]; \??\D:\PowerDVD10\NavFilter\000.fcl []
R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 cpuz132;cpuz132; \??\C:\WINDOWS\system32\drivers\cpuz132_x32.sys []
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-08-05 54752]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys [2009-02-24 116736]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-07-09 10604128]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-06 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-06 12928]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-03-25 130432]
S3 afxzvxs2;afxzvxs2; C:\WINDOWS\system32\drivers\afxzvxs2.sys []
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024]
S3 BTHMODEM;Bluetooth Modem Communications Driver; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-14 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 btkrnl;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-03-10 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-03-10 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-03-10 21456]
S3 mbr;mbr; \??\C:\DOCUME~1\Hong\LOCALS~1\Temp\mbr.sys []
S3 n558;N558 Bluetooth USB Filter Driver; C:\WINDOWS\System32\Drivers\n558.sys [2007-08-15 9600]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-14 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-19 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 u1thmtecye6;PowerUtility TV Recording Reservation; C:\WINDOWS\system32\pyhu.exe [2010-11-22 201216]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-30 46104]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2003-03-10 65795]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S4 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-08-11 655624]
S4 fsssvc;Služba Bezpečnosť rodiny v službe Windows Live; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S4 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-30 881664]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-02-14 152984]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-30 132096]
S4 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-09-04 131072]
S4 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-07-09 155752]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-29 89136]
S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S4 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-19 913408]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Hong at 2010-11-22 18:44:30
Microsoft Windows XP Professional Service Pack 3
System drive C: has 45 GB (46%) free of 98 GB
Total RAM: 2559 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:44:36, on 22.11.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\loosoujouzous.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Hong\Desktop\RSIT.exe
C:\Program Files\trend micro\Hong.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fullarticles.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.games-fusion.net
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mupoga] C:\WINDOWS\system32\loosoujouzous.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: 0o65u1l.exe
O4 - Startup: 0ttzpgw.exe
O4 - Startup: 0x0nt20.exe
O4 - Startup: 5nyj26a.exe
O4 - Startup: 69o1pvg.exe
O4 - Startup: bwsidte0k6.exe
O4 - Startup: c8tzpgwr.exe
O4 - Startup: cc8tzpgwr26.exe
O4 - Startup: ffwrrns7.exe
O4 - Startup: hsydup6a0h.exe
O4 - Startup: ie0aa5b0.exe
O4 - Startup: iy0uk0vgw0.exe
O4 - Startup: lh5syz2k1.exe
O4 - Startup: qb271z2k1g.exe
O4 - Startup: r60ttzpgw.exe
O4 - Startup: rc3oo3avbm0.exe
O4 - Startup: rw3ii3uu.exe
O4 - Startup: rxc3oo3avbm.exe
O4 - Startup: xidzzvlr.exe
O4 - Startup: xy0o3avb.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} - http://go.microsoft.com/fwlink/?linkid=39204
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: PowerUtility TV Recording Reservation (u1thmtecye6) - Unknown owner - C:\WINDOWS\system32\pyhu.exe
--
End of file - 4812 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-FAJKOS-Hong.job
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1275498585.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-839522115-1617979688-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-839522115-1617979688-1003UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"NVMixerTray"=C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe [2004-06-03 131072]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-07-07 1753192]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-07-09 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-07-09 13923432]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"mupoga"=C:\WINDOWS\system32\loosoujouzous.exe [2010-11-22 201216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
C:\Program Files\Cyberlink\Shared files\brs.exe [2010-06-28 75048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-04-12 1135912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Hong\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-24 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.1\ICQ.exe [2010-10-27 133432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-09-04 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2010-07-09 110696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10]
D:\PowerDVD10\PDVD10Serv.exe [2010-02-02 87336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-02-14 148888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2010-07-12 74752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpotdd01.exe [2003-04-06 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^0ddzppl.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\0ddzppl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^5n0tup8.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\5n0tup8.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^a1wssneezq.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\a1wssneezq.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^a3mc1ijj.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\a3mc1ijj.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^Adobe Gamma.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^avbg3ss3.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\avbg3ss3.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^bhxnijjf.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\bhxnijjf.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^cxxotup83.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\cxxotup83.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^fagg3ss3ee1.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\fagg3ss3ee1.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^g70hdyy6k.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\g70hdyy6k.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^i3uuklq8.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\i3uuklq8.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^i3uuklq860.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\i3uuklq860.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^lwhns3ee1q.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\lwhns3ee1q.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^MagicDisc.lnk]
C:\PROGRA~1\MAGICD~1\MAGICD~1.EXE [2009-02-23 576000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^riddzpplq3.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\riddzpplq3.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^rrnddzpplbb.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\rrnddzpplbb.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^s86e81qbcxd.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\s86e81qbcxd.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^uk0g3ss3ee1.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\uk0g3ss3ee1.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^vmmhyytk.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\vmmhyytk.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^w0xnijjfk3.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\w0xnijjfk3.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^whx9ye0k3w.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\whx9ye0k3w.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^WinFlip.lnk]
C:\PROGRA~1\WinFlip\WinFlip.exe [2007-10-25 462848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hong^Start Menu^Programs^Startup^y8703g0hxd6.exe]
C:\Documents and Settings\Hong\Start Menu\Programs\Startup\y8703g0hxd6.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3
"idsvc"=3
"ICQ Service"=2
"WZCSVC"=2
"wuauserv"=2
"wscsvc"=2
"JavaQuickStarterService"=2
"NetTcpPortSharing"=2
"WMPNetworkSvc"=3
"gusvc"=2
"gupdate1c9aca3419ed106"=2
"Viewpoint Manager Service"=2
"MDM"=2
"Adobe LM Service"=3
"ServiceLayer"=3
"IDriverT"=3
"fsssvc"=3
"FLEXnet Licensing Service"=3
"nvsvc"=2
"nTuneService"=2
"CachemanXPService"=3
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Documents and Settings\Hong\Start Menu\Programs\Startup
0o65u1l.exe
0ttzpgw.exe
0x0nt20.exe
5nyj26a.exe
69o1pvg.exe
bwsidte0k6.exe
c8tzpgwr.exe
cc8tzpgwr26.exe
ffwrrns7.exe
hsydup6a0h.exe
ie0aa5b0.exe
iy0uk0vgw0.exe
lh5syz2k1.exe
qb271z2k1g.exe
r60ttzpgw.exe
rc3oo3avbm0.exe
rw3ii3uu.exe
rxc3oo3avbm.exe
xidzzvlr.exe
xy0o3avb.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
WgaLogon.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-19 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoSMBalloonTip"=0
"NoDesktopCleanupWizard"=1
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoResolveSearch"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
======List of files/folders created in the last 1 months======
2010-11-22 18:42:01 ----D---- C:\WINDOWS\temp
2010-11-22 18:41:59 ----A---- C:\ComboFix.txt
2010-11-22 15:56:40 ----A---- C:\WINDOWS\system32\pyhu.exe
2010-11-22 15:56:24 ----RA---- C:\Documents and Settings\Hong\Application Data\BG0Ai.txt
2010-11-22 15:56:23 ----A---- C:\WINDOWS\system32\loosoujouzous.exe
2010-11-21 18:50:36 ----D---- C:\Documents and Settings\Hong\Application Data\Mumble
2010-11-21 18:50:03 ----D---- C:\Program Files\Mumble
2010-11-20 22:17:16 ----D---- C:\Program Files\The KMPlayer
2010-11-16 19:48:08 ----A---- C:\WINDOWS\IE4 Error Log.txt
2010-11-15 22:58:12 ----D---- C:\Documents and Settings\Hong\Application Data\TS3Client
2010-11-15 22:57:55 ----D---- C:\Program Files\TeamSpeak 3 Client
2010-11-14 21:42:33 ----D---- C:\Config.Msi
2010-11-14 19:02:10 ----RASHD---- C:\cmdcons
2010-11-14 18:44:16 ----D---- C:\rsit
2010-11-14 18:23:48 ----A---- C:\WINDOWS\zip.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\SWSC.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\SWREG.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\sed.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\PEV.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\NIRCMD.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\MBR.exe
2010-11-14 18:23:48 ----A---- C:\WINDOWS\grep.exe
2010-11-14 18:22:58 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-11-14 18:19:23 ----D---- C:\WINDOWS\ERDNT
2010-11-14 18:16:50 ----AD---- C:\Qoobox
2010-11-14 17:49:13 ----A---- C:\WINDOWS\ntbtlog.txt
2010-11-14 17:44:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-11-14 13:10:32 ----A---- C:\WINDOWS\wininit.ini
2010-11-13 19:36:38 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-11-13 19:36:38 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-10-28 22:42:20 ----D---- C:\Documents and Settings\All Users\Application Data\Trymedia
======List of files/folders modified in the last 1 months======
2010-11-22 18:44:32 ----D---- C:\Program Files\Trend Micro
2010-11-22 18:42:01 ----D---- C:\WINDOWS\system32\drivers
2010-11-22 18:42:01 ----D---- C:\WINDOWS
2010-11-22 18:40:05 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-22 18:37:39 ----A---- C:\WINDOWS\system.ini
2010-11-22 18:37:19 ----D---- C:\WINDOWS\system32\drivers\etc
2010-11-22 18:34:20 ----D---- C:\WINDOWS\system32
2010-11-22 18:34:20 ----D---- C:\WINDOWS\AppPatch
2010-11-22 18:34:19 ----D---- C:\Program Files\Common Files
2010-11-22 18:20:45 ----D---- C:\WINDOWS\system32\config
2010-11-22 18:01:07 ----D---- C:\WINDOWS\Prefetch
2010-11-22 15:20:21 ----D---- C:\Documents and Settings\Hong\Application Data\ICQ
2010-11-21 20:44:09 ----A---- C:\WINDOWS\win.ini
2010-11-21 18:50:03 ----RD---- C:\Program Files
2010-11-20 22:15:36 ----D---- C:\Documents and Settings\Hong\Application Data\vlc
2010-11-18 21:21:35 ----SD---- C:\WINDOWS\Tasks
2010-11-18 11:25:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-11-14 21:47:45 ----D---- C:\WINDOWS\pss
2010-11-14 21:42:39 ----SHD---- C:\WINDOWS\Installer
2010-11-14 21:42:28 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-11-14 19:02:16 ----RASH---- C:\boot.ini
2010-11-14 18:29:14 ----HD---- C:\WINDOWS\inf
2010-11-14 18:22:53 ----D---- C:\WINDOWS\WinSxS
2010-11-14 17:49:20 ----SHD---- C:\WINDOWS\CSC
2010-11-14 17:41:58 ----D---- C:\WINDOWS\system32\LogFiles
2010-11-14 17:30:46 ----D---- C:\WINDOWS\system32\appmgmt
2010-11-14 17:13:58 ----A---- C:\Boot.bak
2010-11-12 11:24:44 ----A---- C:\WINDOWS\NeroDigital.ini
2010-11-10 16:47:27 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-11-10 16:47:07 ----D---- C:\Program Files\Adobe
2010-11-10 16:46:56 ----D---- C:\Program Files\Common Files\Adobe
2010-11-03 16:24:36 ----D---- C:\Documents and Settings\Hong\Application Data\uTorrent
2010-11-03 14:34:41 ----D---- C:\Documents and Settings\All Users\Application Data\Blizzard Entertainment
2010-11-02 18:52:46 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2010-10-31 23:24:24 ----D---- C:\Program Files\ICQ7.1
2010-10-28 22:30:23 ----RSD---- C:\WINDOWS\assembly
2010-10-28 22:30:04 ----D---- C:\WINDOWS\system32\DirectX
2010-10-26 15:59:15 ----D---- C:\Documents and Settings\Hong\Application Data\SystemRequirementsLab
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2004-04-02 21760]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-04-22 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2010-06-02 82380]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 36864]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/07/11 13:05:02]; \??\D:\PowerDVD10\NavFilter\000.fcl []
R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 cpuz132;cpuz132; \??\C:\WINDOWS\system32\drivers\cpuz132_x32.sys []
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-08-05 54752]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys [2009-02-24 116736]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-07-09 10604128]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-06 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-06 12928]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-03-25 130432]
S3 afxzvxs2;afxzvxs2; C:\WINDOWS\system32\drivers\afxzvxs2.sys []
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024]
S3 BTHMODEM;Bluetooth Modem Communications Driver; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-14 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944]
S3 btkrnl;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-03-10 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-03-10 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-03-10 21456]
S3 mbr;mbr; \??\C:\DOCUME~1\Hong\LOCALS~1\Temp\mbr.sys []
S3 n558;N558 Bluetooth USB Filter Driver; C:\WINDOWS\System32\Drivers\n558.sys [2007-08-15 9600]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-14 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-19 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 u1thmtecye6;PowerUtility TV Recording Reservation; C:\WINDOWS\system32\pyhu.exe [2010-11-22 201216]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-30 46104]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2003-03-10 65795]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S4 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-08-11 655624]
S4 fsssvc;Služba Bezpečnosť rodiny v službe Windows Live; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S4 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-30 881664]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-02-14 152984]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-30 132096]
S4 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-09-04 131072]
S4 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-07-09 155752]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-29 89136]
S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S4 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-19 913408]
-----------------EOF-----------------