sorry, this is the fixed information
Logfile of random's system information tool 1.04 (written by random/random)
Run by ir8clan at 2008-10-31 13:41:49
Microsoft Windows XP Professional Service Pack 2
System drive C: has 79 GB (86%) free of 92 GB
Total RAM: 959 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:41:49, on 10/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\o2flash.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SkyTel.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Zeallsoft\Super Screen Capture\SSCapture.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Documents and Settings\ir8clan\Application Data\Google\mupd1_2_1165664.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Documents and Settings\ir8clan\Desktop\RSIT.exe
C:\Program Files\trend micro\ir8clan.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about
:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: CKeyScramblerBHO Object - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll (file missing)
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0311.0\msneshellx.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Super Screen Capture] C:\Program Files\Zeallsoft\Super Screen Capture\SSCapture.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [asus32] "C:\Documents and Settings\ir8clan\Application Data\Google\mupd1_2_1165664.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RealUpgradeHelper] "C:\Program Files\Common Files\Real\Update_OB\upgrdhlp.exe" "RealNetworks|RealPlayer|6.0" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [KeyScrambler] C:\Program Files\KeyScrambler\getting_started.html (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RealUpgradeHelper] "C:\Program Files\Common Files\Real\Update_OB\upgrdhlp.exe" "RealNetworks|RealPlayer|6.0" (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.com/content/Driver...sysreqlab2.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) -
http://www.nvidia.com/content/Driver...aSmartScan.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
--
End of file - 9496 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\SpywareStop Scheduled Scan.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2008-02-18 99760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2B9F5787-88A5-4945-90E7-C4B18563BC5E}]
CKeyScramblerBHO Object - C:\Program Files\KeyScrambler\KeyScramblerIE.dll [2008-12-28 812520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-12-15 308856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-07-07 1562448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - MSN Toolbar - C:\Program Files\MSN\Toolbar\3.0.0311.0\msneshellx.dll [2008-06-03 86032]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-05-04 16206848]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-04-24 1448960]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-02-01 8523776]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-02-01 81920]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"Super Screen Capture"=C:\Program Files\Zeallsoft\Super Screen Capture\SSCapture.exe [2006-06-02 3126784]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-12-15 185896]
"SpyHunter Security Suite"=C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe []
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-03 15360]
"Yahoo! Pager"=C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE [2007-08-30 4670704]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2008-01-23 2577840]
"DW6"=C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe [2008-06-10 785520]
"asus32"=C:\Documents and Settings\ir8clan\Application Data\Google\mupd1_2_1165664.exe [2008-12-28 98304]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-07-07 2156368]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Ralink Wireless Utility.lnk - C:\Program Files\RALINK\Common\RaUI.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e052900-276a-11dd-84b8-0040452c13e8}]
shell\AutoRun\command - E:\wd_windows_tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f85bd0d0-60db-11dd-84ef-0013d380508d}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
shell\Open(&0)\command - Recycled\ctfmon.exe
======File associations======
.txt - open - Notepad.exe %1
======List of files/folders created in the last 1 months======
2008-12-30 15:18:53 ----D---- C:\WINDOWS\Minidump
2008-12-30 13:57:57 ----SHD---- C:\RECYCLER
2008-12-30 13:39:35 ----D---- C:\WINDOWS\temp
2008-12-30 13:39:34 ----A---- C:\ComboFix.txt
2008-12-30 13:35:44 ----A---- C:\Boot.bak
2008-12-30 13:35:34 ----RASHD---- C:\cmdcons
2008-12-30 13:34:27 ----A---- C:\WINDOWS\zip.exe
2008-12-30 13:34:27 ----A---- C:\WINDOWS\VFIND.exe
2008-12-30 13:34:27 ----A---- C:\WINDOWS\SWXCACLS.exe
2008-12-30 13:34:27 ----A---- C:\WINDOWS\SWSC.exe
2008-12-30 13:34:27 ----A---- C:\WINDOWS\SWREG.exe
2008-12-30 13:34:27 ----A---- C:\WINDOWS\sed.exe
2008-12-30 13:34:27 ----A---- C:\WINDOWS\NIRCMD.exe
2008-12-30 13:34:27 ----A---- C:\WINDOWS\grep.exe
2008-12-30 13:34:27 ----A---- C:\WINDOWS\fdsv.exe
2008-12-30 13:34:05 ----D---- C:\WINDOWS\ERDNT
2008-12-30 13:34:05 ----D---- C:\Qoobox
2008-12-30 13:29:27 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-12-30 13:29:27 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-29 23:27:41 ----D---- C:\Program Files\trend micro
2008-12-29 22:45:08 ----A---- C:\WINDOWS\gmer.ini
2008-12-29 22:45:04 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2008-12-29 22:45:04 ----A---- C:\WINDOWS\gmer.exe
2008-12-29 22:45:04 ----A---- C:\WINDOWS\gmer.dll
2008-12-28 22:42:54 ----D---- C:\Program Files\Enigma Software Group
2008-12-28 22:21:25 ----D---- C:\Program Files\CCleaner
2008-12-28 20:45:34 ----D---- C:\Program Files\KeyScrambler
2008-12-28 20:05:45 ----A---- C:\IPAddr.txt
2008-12-28 20:05:16 ----A---- C:\phyaddr.txt
2008-12-28 19:54:53 ----A---- C:\ipconfig.txt
2008-12-28 18:44:21 ----D---- C:\Documents and Settings\ir8clan\Application Data\Google
2008-12-28 10:13:50 ----D---- C:\Program Files\ImTOO
2008-12-27 11:19:00 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-12-15 18:17:04 ----D---- C:\Program Files\Common Files\xing shared
2008-12-15 04:15:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-12-15 04:15:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-12-15 04:14:37 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-12-15 04:13:56 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-12-15 04:10:06 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-12-15 04:04:39 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
2008-12-15 03:17:42 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-15 02:59:22 ----D---- C:\Documents and Settings\ir8clan\Application Data\Malwarebytes
2008-12-15 02:59:09 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-15 01:11:10 ----D---- C:\WINDOWS\system32\appmgmt
2008-12-13 22:55:16 ----D---- C:\Documents and Settings\ir8clan\Application Data\skypePM
2008-12-13 22:49:51 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2008-11-23 23:38:23 ----D---- C:\Program Files\Samsung
2008-11-11 09:37:31 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-11-11 09:35:50 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-11-03 12:18:16 ----N---- C:\WINDOWS\Setup1.exe
2008-11-03 12:18:15 ----A---- C:\WINDOWS\ST6UNST.EXE
2008-11-03 12:15:00 ----A---- C:\WINDOWS\IsUninst.exe
2008-10-31 13:41:49 ----D---- C:\rsit
2008-10-28 16:57:08 ----D---- C:\WINDOWS\system32\CatRoot_bak
2008-10-15 19

15 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-10-15 19:05:58 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-10-15 19:05:43 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$
2008-10-15 19:05:26 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-10-15 19:05:10 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-10-15 19:04:51 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-10-15 19:04:33 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-10-15 19:03:52 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$
2008-10-05 18

09 ----D---- C:\Mp3 Output
2008-10-05 18

04 ----D---- C:\Program Files\Smallvideosoft
2008-10-05 18

04 ----A---- C:\WINDOWS\system32\xvidcore.dll
2008-10-05 18

04 ----A---- C:\WINDOWS\system32\NCMedia.dll
2008-10-05 18

04 ----A---- C:\WINDOWS\system32\libmp3lame-0.dll
2008-10-05 02:05:39 ----D---- C:\Documents and Settings\ir8clan\Application Data\AVS4YOU
2008-10-05 02:05:13 ----D---- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-10-05 02:02:17 ----D---- C:\Program Files\Common Files\AVSMedia
2008-10-05 02:02:11 ----A---- C:\WINDOWS\system32\msvcp70.dll
2008-10-05 02:02:11 ----A---- C:\WINDOWS\system32\mfc70.dll
2008-10-05 02:02:10 ----D---- C:\Program Files\AVS4YOU
2008-10-05 02:02:10 ----A---- C:\WINDOWS\system32\msxml3a.dll
2008-10-05 02:02:10 ----A---- C:\WINDOWS\system32\msvcr70.dll
2008-10-05 02:02:10 ----A---- C:\WINDOWS\system32\GdiPlus.dll
======List of files/folders modified in the last 1 months======
2008-12-31 13:31:49 ----D---- C:\Program Files\Mozilla Firefox
2008-12-31 13:29:49 ----D---- C:\Documents and Settings\ir8clan\Application Data\DMCache
2008-12-31 13:29:04 ----D---- C:\WINDOWS\system32
2008-12-31 13:28:29 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-12-31 13:28:14 ----D---- C:\WINDOWS\system32\drivers
2008-12-31 13:28:14 ----D---- C:\WINDOWS
2008-12-31 13:28:13 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2008-12-31 13:27:16 ----SD---- C:\Documents and Settings\ir8clan\Application Data\Microsoft
2008-12-31 13:23:45 ----RD---- C:\Program Files
2008-12-31 12:24:01 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-12-31 12:19:55 ----D---- C:\Documents and Settings\ir8clan\Application Data\LimeWire
2008-12-30 13:39:34 ----D---- C:\WINDOWS\Prefetch
2008-12-30 13:38:05 ----D---- C:\WINDOWS\system32\CatRoot2
2008-12-30 13:37:14 ----A---- C:\WINDOWS\system.ini
2008-12-30 13:35:44 ----RASH---- C:\boot.ini
2008-12-29 17:37:12 ----D---- C:\Program Files\Bkav2006
2008-12-29 00:25:10 ----SD---- C:\WINDOWS\Tasks
2008-12-29 00:12:49 ----D---- C:\Downloads
2008-12-28 23:51:10 ----D---- C:\Documents and Settings\ir8clan\Application Data\Yahoo!
2008-12-28 23:45:23 ----D---- C:\Documents and Settings\ir8clan\Application Data\SpywareStop
2008-12-28 23:14:07 ----A---- C:\WINDOWS\NeroDigital.ini
2008-12-28 22:32:29 ----D---- C:\WINDOWS\Debug
2008-12-28 19:37:48 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-28 18:45:23 ----D---- C:\Documents and Settings\ir8clan\Application Data\Ahead
2008-12-28 18:45:23 ----D---- C:\Documents and Settings\ir8clan\Application Data\AdobeUM
2008-12-28 18:45:23 ----D---- C:\Documents and Settings\ir8clan\Application Data\Adobe
2008-12-28 18:45:22 ----D---- C:\Documents and Settings\ir8clan\Application Data\Adblock Pro
2008-12-27 11:19:16 ----HD---- C:\WINDOWS\inf
2008-12-27 11:19:04 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-27 11:17:08 ----HD---- C:\WINDOWS\$hf_mig$
2008-12-15 18:17:04 ----D---- C:\Program Files\Common Files
2008-12-15 18:16:53 ----D---- C:\Program Files\Common Files\Real
2008-12-15 18:16:45 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2008-12-15 18:16:30 ----A---- C:\WINDOWS\system32\pndx5032.dll
2008-12-15 18:16:30 ----A---- C:\WINDOWS\system32\pndx5016.dll
2008-12-15 18:16:20 ----A---- C:\WINDOWS\system32\msvcr71.dll
2008-12-15 18:16:20 ----A---- C:\WINDOWS\system32\msvcp71.dll
2008-12-15 18:16:19 ----A---- C:\WINDOWS\system32\pncrt.dll
2008-12-15 04:05:11 ----D---- C:\Program Files\Internet Explorer
2008-12-15 03:01:50 ----A---- C:\YServer.txt
2008-12-15 01:11:09 ----SHD---- C:\WINDOWS\Installer
2008-12-15 01:00:52 ----D---- C:\Documents and Settings\ir8clan\Application Data\IDM
2008-11-28 19:08:06 ----HD---- C:\Program Files\InstallShield Installation Information
2008-11-11 09:37:32 ----D---- C:\WINDOWS\WinSxS
2008-11-02 17:30:03 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-28 17:35:53 ----D---- C:\WINDOWS\system32\CatRoot
2008-10-28 16:52:03 ----D---- C:\WINDOWS\Help
2008-10-18 02:19:00 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2008-10-15 22:22:35 ----A---- C:\WINDOWS\PhotoSnapViewer.INI
2008-10-15 19

00 ----D---- C:\Program Files\Messenger
2008-10-15 09:57:55 ----A---- C:\WINDOWS\system32\netapi32.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 SysLib;SysLib; C:\WINDOWS\system32\drivers\SysLib.sys [2008-12-29 15979350]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-03-12 20747]
R3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2008-12-29 85969]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-05-04 4271616]
R3 KeyScrambler;KeyScrambler; C:\WINDOWS\System32\drivers\keyscrambler.sys [2008-06-24 113896]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-02-01 7434720]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-02-17 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-02-17 13056]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 11136]
R3 RT73;RT73 USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt73.sys [2006-01-12 252928]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera; C:\WINDOWS\System32\Drivers\ubVeo532.sys [2002-07-01 95232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NtApm;NT Apm/Legacy Interface Driver; C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 9344]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-03 67584]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 ACPI;ACPI; C:\WINDOWS\system32\drivers\ACPI.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-20 168432]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-02-01 155716]
R2 O2Flash;O2Micro Flash Memory; C:\WINDOWS\system32\o2flash.exe [2006-08-15 36864]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-03 14336]
-----------------EOF-----------------