Infected - "Win Anti Spyware" "Buffer overrun error" and a fake dialer or something++
I've been having some problems with my computer and I've always somehow managed to work my way around the issues spyware/malware etc. have created but lately it's been getting out of hand.. Some time ago I got a virus or something that made the entire tab under "Processes" dissapear. So I could not see process-names in the task-manager. I have re-installed XP but this problem persists. I have been using a different application to monitor and handle processes.
The problem now is the constant pop-ups generated from this fake anti-virus program calling itself "Anti Virus Pro 2007" or something.. It pops up with fake commercials, and even attach itself into other explorer-windows while I view other pages.
As popups and messageboxes keep popping up, I close them, but after a while windows will open a messagebox telling me "Buffer overrun detected in e:\Windows\system32\explorer.exe" (or \\windows\explorer.exe I don't remember really but you get the idea) and explorer.exe will be terminated, sometimes taking some internet explorer windows along with it, other times explorer.exe just starts up again and all my windows remain.
I used to have Norton but was forced to remove it as it was sucking up all my CPU. It rendered my computer useless, as I mainly use it for gaming.
I've also experienced having the connection between me and my modem broken while beeing on the internet, and I don't know if my computer actually is offline or if -I'm- just offline.. The LAN-connection won't detect my modem and I can't even find it by pinging it.
I have been trough Step 1 without finding anything I could remove in control-panel.
The panda online search take hours if not days to finish, as it slows down severly after a certain time.. I have tried acouple of times but before it finish a popup or an error will close the browser window :/
EDIT: I forgot to mention.. I have tried to follow acouple of solutions I saw you guys giving people with similiar problems as I had, and searching for malware and stuff it did find some infected dll-files in my system32 folder and other windows-folders. I deleted afew but something called nnommmll.dll or something was attached to winlogon.exe and therefore I couldn't delete it. The other files came back after my computer crashed anyway though x.x
I'll now paste the logfile generated by dss.exe
----------------------------------------------------
Deckard's System Scanner v20070905.67
Run by Per_Killer on 2007-10-04 02:29:20
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 4 Restore Point(s) --
4: 2007-10-04 00:29:26 UTC - RP203 - Deckard's System Scanner Restore Point
3: 2007-10-03 17:36:54 UTC - RP202 - Kontrollpunkt for system
2: 2007-10-02 05:58:08 UTC - RP201 - Kontrollpunkt for system
1: 2007-09-29 10:08:40 UTC - RP200 - Kontrollpunkt for system
Backed up registry hives.
Performed disk cleanup.
System Drive E: has 10.05 GiB (less than 15%) free.
-- HijackThis (run as Per_Killer.exe) ------------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-10-04 02:32:11
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Running processes:
E:\WINDOWS\system32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\CTSVCCDA.EXE
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\PnkBstrA.exe
E:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\wscntfy.exe
H:\Prog\Java\bin\jusched.exe
E:\WINDOWS\system32\LVCOMSX.EXE
E:\Programfiler\Analog Devices\SoundMAX\SMTray.exe
E:\Programfiler\MSN Messenger\msnmsgr.exe
E:\Programfiler\MSN Messenger\usnsvc.exe
C:\Prog\Mirc\mirc.exe
E:\WINDOWS\explorer.exe
H:\Sindre\Spill\Online\Dark Ages\DarkAges.exe
E:\Programfiler\iPod\bin\iPodService.exe
E:\Programfiler\Internet Explorer\iexplore.exe
E:\Documents and Settings\Per_Killer\Skrivebord\FIX\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - H:\Prog\SnagIt\SnagItBHO.dll
O2 - BHO: (no name) - {02633FD6-4FBE-47B1-8966-7C223969A25B} - (no file)
O2 - BHO: (no name) - {709AFF26-6BB0-4AD3-A3A3-1286592465D6} - E:\WINDOWS\system32\nnnomml.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Prog\Java\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9B5CFE0B-BE3B-4552-811D-84539C0DCFA5} - E:\WINDOWS\system32\mljgh.dll
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - E:\WINDOWS\system32\trxxmaxe.dll
O2 - BHO: (no name) - {E980DD43-BEDE-46DD-BC03-BB7B85544898} - E:\WINDOWS\system32\ukwhuvtf.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - H:\Prog\SnagIt\SnagItIEAddin.dll
O4 - HKEY_LOCAL_MACHINE\..\Run: [SunJavaUpdateSched] "H:\Prog\Java\bin\jusched.exe"
O4 - HKEY_LOCAL_MACHINE\..\Run: [LVCOMSX] E:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKEY_LOCAL_MACHINE\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKEY_LOCAL_MACHINE\..\Run: [nwiz] nwiz.exe /install
O4 - HKEY_LOCAL_MACHINE\..\Run: [Smapp] E:\Programfiler\Analog Devices\SoundMAX\SMTray.exe
O4 - HKEY_LOCAL_MACHINE\..\Run: [QuickTime Task] "E:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKEY_LOCAL_MACHINE\..\Run: [PKR Pal] "H:\Sindre\Spill\PKR\pkrpal.exe" -osboot
O4 - HKEY_LOCAL_MACHINE\..\Run: [PWRISOVM.EXE] H:\Prog\PowerISO\PWRISOVM.EXE
O4 - HKEY_LOCAL_MACHINE\..\Run: [SearchIndexer] rundll32.exe "E:\WINDOWS\system32\ymqwfikn.dll",sitypnow
O4 - HKEY_LOCAL_MACHINE\..\RunOnce: [*CmaudioMon] rundll32.exe bot007dll.dll,_EntryPoint@16
O4 - HKCU\..\Run: [MsnMsgr] "E:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = E:\Programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Registration .LNK = H:\Sindre\Spill\Dark Messiah\Dark Messiah of Might and Magic\RegistrationReminder.exe
O8 - Extra context menu item: Download All Links with IDM - C:\Prog\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Prog\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Prog\Java\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Prog\Java\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - E:\Documents and Settings\Per_Killer\Start-meny\Programmer\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - E:\Documents and Settings\Per_Killer\Start-meny\Programmer\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {44226DFF-747E-4edc-B30C-78752E50CD0C} - (file missing)
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - H:\Sindre\Spill\PokerGames\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - H:\Sindre\Spill\PokerGames\Titan Poker\casino.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\Programfiler\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\Programfiler\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programfiler\Messenger\msmsgs.exe
O16 - DPF: {0A50726E-51A2-42BB-8392-98F050C40A10} (SkillJamLoader Class) - http://rcade.skilljam.com/ssp/SkillJamLoader.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) - http://www.powerflasher.de/plugin/powerres.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://www.cherrytreeinn.com:8080/kxhcm10.ocx
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab Class) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - E:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - E:\Programfiler\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - E:\Programfiler\MSN Messenger\msgrapp.8.1.0178.00.dll
O20 - Winlogon Notify: AtiExtEvent - E:\WINDOWS\system32\
O20 - Winlogon Notify: mljgh - E:\WINDOWS\system32\mljgh.dll
O20 - Winlogon Notify: nnnomml - E:\WINDOWS\system32\nnnomml.dll
O20 - Winlogon Notify: ssttt - E:\WINDOWS\system32\ssttt.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - "E:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe"
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - E:\WINDOWS\system32\CTSVCCDA.EXE
O23 - Service: DomainService - Unknown owner - E:\WINDOWS\system32\uflpuqca.exe /service
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "E:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe"
O23 - Service: iPodService - Apple Computer, Inc. - E:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - "E:\Programfiler\Fellesfiler\Macromedia Shared\Service\Macromedia Licensing.exe"
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
-- HijackThis Fixed Entries (H:\Prog\HIJACK~1\backups\) ------------------------
backup-20061130-055756-706 O2 - BHO: °Ù¶È³¬¼¶ËÑ°Ô - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - E:\Progra~1\Baidu\bar\BaiDuBar.dll
backup-20061130-055840-122 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Prog\Java\jre1.5.0_06\bin\ssv.dll
backup-20061130-055840-766 O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
backup-20061130-055840-841 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Prog\Spybot - Search & Destroy\SDHelper.dll
backup-20061130-055850-443 O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Prog\Internet Download Manager\IDMIECC.dll
backup-20061130-055913-313 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Prog\Adobe Reader\Reader\ActiveX\AcroIEHelper.dll
backup-20061130-055937-730 R3 - Default URLSearchHook is missing
backup-20061130-060029-107 O8 - Extra context menu item: °Ù¶È-ËÑË÷ÐÂÎÅ - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM
backup-20061130-060029-200 O8 - Extra context menu item: °Ù¶È-ËÑË÷ͼƬ - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM
backup-20061130-060029-247 O8 - Extra context menu item: °Ù¶È-ËÑË÷¸è´Ê - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM
backup-20061130-060029-510 O8 - Extra context menu item: °Ù¶È-ËÑË÷MP3 - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM
backup-20061130-060029-755 O8 - Extra context menu item: °Ù¶È-´ÊµäËÑË÷ - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM
backup-20061130-060029-770 O8 - Extra context menu item: °Ù¶È-ËÑË÷Ìù°É - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM
backup-20061130-060029-832 O8 - Extra context menu item: °Ù¶È-ËÑË÷ÍøÒ³ - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM
backup-20061130-060102-266 O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Sindre\Spill\PokerGames\PartyPoker\PartyPoker\RunApp.exe
backup-20061130-060102-369 O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - E:\Sindre\Spill\POKER\Poker.com\poker.exe
backup-20061130-060102-390 O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Sindre\Spill\PokerGames\PartyPoker\PartyPoker\RunApp.exe
backup-20061130-060102-691 O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - E:\Sindre\Spill\POKER\Noble Poker\casino.exe
backup-20061130-060102-838 O9 - Extra button: CDpoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - E:\Sindre\Spill\POKER\CDpoker\casino.exe
backup-20061130-060103-144 O9 - Extra 'Tools' menuitem: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - E:\Documents and Settings\All Users\Start-meny\Programmer\Absolute Poker\Absolute Poker.lnk (file missing)
backup-20061130-060103-568 O9 - Extra button: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - E:\Documents and Settings\All Users\Start-meny\Programmer\Absolute Poker\Absolute Poker.lnk (file missing)
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - e:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - e:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - e:\windows\system32\drivers\sfvfs02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 SCDEmu - e:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R2 CdaD10BA - e:\windows\system32\drivers\cdad10ba.sys <Not Verified; Macrovision Europe Ltd; Security Windows NT>
R2 ithsgt - e:\windows\system32\drivers\ithsgt.sys
R2 lilsgt - e:\windows\system32\drivers\lilsgt.sys
R3 scskusbf (USB SCSK Filter Driver Service) - e:\windows\system32\drivers\scskusbf.sys <Not Verified; SoftCamp; SCSKUSBf 4.0.1.6>
R3 scskusbs (USB SCSK Driver Service) - e:\windows\system32\drivers\scskusbs.sys <Not Verified; SoftCamp; SCSKUSBs 4.0.1.6>
R3 Tetris (Tetris driver) - e:\windows\system32\drivers\tetris.sys
S2 zntport (NTPort Library Driver) - e:\windows\system32\zntport.sys (file missing)
S3 EagleNT - e:\windows\system32\drivers\eaglent.sys (file missing)
S3 FreshIO - h:\prog\freshdiagnose\freshio.sys
S3 KLIF - c:\prog\pctool~1\klif.sys (file missing)
S3 scsk4 (SCSK4 Driver Service) - e:\windows\system32\drivers\scsk4.sys <Not Verified; SoftCamp Co., Inc.; SoftCamp Secure KeyStroke>
S3 XDva004 - e:\windows\system32\xdva004.sys (file missing)
S3 XTrapD12 - e:\windows\system32\xtrapd12.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 DomainService - e:\windows\system32\uflpuqca.exe /service (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2007-09-04 and 2007-10-04 -----------------------------
2007-10-03 21:39:22 76412 --a------ E:\WINDOWS\system32\lgdlbcwi.dll
2007-10-03 21:33:10 82964 --a------ E:\WINDOWS\system32\ymqwfikn.dll
2007-10-03 21:30:27 75284 --a------ E:\WINDOWS\system32\ltridbwa.exe <Not Verified; ; DDC>
2007-10-03 21:23:06 0 d-------- E:\WINDOWS\system32\ActiveScan
2007-10-03 21:23:04 0 d-------- E:\WINDOWS\LastGood
2007-10-03 17:56:26 82964 --a------ E:\WINDOWS\system32\giypnwod.dll
2007-10-03 17:53:34 75284 --a------ E:\WINDOWS\system32\fbyghkdt.exe <Not Verified; ; DDC>
2007-10-03 16:57:58 82964 -----n--- E:\WINDOWS\system32\dnmtpwpx.dll
2007-10-03 16:55:08 75284 --a------ E:\WINDOWS\system32\tdedrhik.exe <Not Verified; ; DDC>
2007-10-03 16:15:16 82964 --a------ E:\WINDOWS\system32\vaipaolq.dll
2007-10-03 16:12:28 75284 --a------ E:\WINDOWS\system32\kfcxdptg.exe <Not Verified; ; DDC>
2007-10-03 15:40:03 543656 ---hs---- E:\WINDOWS\system32\hgjlm.ini2
2007-10-02 22:28:47 82964 --a------ E:\WINDOWS\system32\itscdfva.dll
2007-10-02 22:25:57 75284 --a------ E:\WINDOWS\system32\cpvhguli.exe <Not Verified; ; DDC>
2007-10-02 22:23:06 75284 --a------ E:\WINDOWS\system32\iuhsdtss.exe <Not Verified; ; DDC>
2007-10-02 19:22:36 82964 --a------ E:\WINDOWS\system32\qkglxptl.dll
2007-10-02 19:19:36 75284 --a------ E:\WINDOWS\system32\kvqigrpj.exe <Not Verified; ; DDC>
2007-10-02 19:16:37 75284 --a------ E:\WINDOWS\system32\hqngeotd.exe <Not Verified; ; DDC>
2007-10-02 18:58:01 82964 --a------ E:\WINDOWS\system32\abwlxwrg.dll
2007-10-02 18:58:00 75284 --a------ E:\WINDOWS\system32\fhbdfhbp.exe <Not Verified; ; DDC>
2007-10-02 18:53:13 82964 --a------ E:\WINDOWS\system32\xydvsbfo.dll
2007-10-02 18:50:25 75284 --a------ E:\WINDOWS\system32\msvrjkxu.exe <Not Verified; ; DDC>
2007-10-02 18:47:34 75284 --a------ E:\WINDOWS\system32\wjffaynk.exe <Not Verified; ; DDC>
2007-10-02 18:23:06 82964 --a------ E:\WINDOWS\system32\ehhqxite.dll
2007-10-02 18:05:56 75284 --a------ E:\WINDOWS\system32\nykvengt.exe <Not Verified; ; DDC>
2007-10-02 17:16:23 75284 --a------ E:\WINDOWS\system32\kfoheveo.exe <Not Verified; ; DDC>
2007-10-02 17:13:24 75284 --a------ E:\WINDOWS\system32\idrunlti.exe <Not Verified; ; DDC>
2007-10-02 16:26:16 82964 --a------ E:\WINDOWS\system32\sbqqaysh.dll
2007-10-02 16:23:05 75284 --a------ E:\WINDOWS\system32\liugktpa.exe <Not Verified; ; DDC>
2007-10-02 15:50:00 82964 --a------ E:\WINDOWS\system32\ymdknvym.dll
2007-10-02 15:49:59 75284 --a------ E:\WINDOWS\system32\kplrlyop.exe <Not Verified; ; DDC>
2007-10-02 15:46:59 75284 --a------ E:\WINDOWS\system32\liildpvt.exe <Not Verified; ; DDC>
2007-10-02 07:43:56 75284 --a------ E:\WINDOWS\system32\oqjxmygl.exe <Not Verified; ; DDC>
2007-10-02 07:40:57 75284 --a------ E:\WINDOWS\system32\leemlqxm.exe <Not Verified; ; DDC>
2007-10-02 07:21:28 82964 --a------ E:\WINDOWS\system32\cmaudyql.dll
2007-10-02 07:20:30 314368 --a------ E:\WINDOWS\uninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2007-10-02 07:18:28 75284 --a------ E:\WINDOWS\system32\oxbpsifa.exe <Not Verified; ; DDC>
2007-10-02 07:15:35 75284 --a------ E:\WINDOWS\system32\otgambbm.exe <Not Verified; ; DDC>
2007-10-02 02:20:15 75284 --a------ E:\WINDOWS\system32\pjfgbnoj.exe <Not Verified; ; DDC>
2007-10-02 01:10:14 82964 --a------ E:\WINDOWS\system32\rwpkrfhf.dll
2007-10-02 01:04:20 75284 --a------ E:\WINDOWS\system32\smhrxgch.exe <Not Verified; ; DDC>
2007-10-02 01:00:42 82964 --a------ E:\WINDOWS\system32\vrpifpcc.dll
2007-10-02 00:57:43 121364 --a------ E:\WINDOWS\system32\ukwhuvtf.dll
2007-10-02 00:57:41 75284 --a------ E:\WINDOWS\system32\powoncmw.exe <Not Verified; ; DDC>
2007-10-02 00:54:42 75284 --a------ E:\WINDOWS\system32\pbggysns.exe <Not Verified; ; DDC>
2007-10-02 00:42:17 82964 --a------ E:\WINDOWS\system32\lwnenddr.dll
2007-10-02 00:36:25 75284 --a------ E:\WINDOWS\system32\onburapy.exe <Not Verified; ; DDC>
2007-10-02 00:02:59 82964 --a------ E:\WINDOWS\system32\eycqhfep.dll
2007-10-01 23:54:14 75284 --a------ E:\WINDOWS\system32\fxxhumhy.exe <Not Verified; ; DDC>
2007-10-01 19:56:18 82964 --a------ E:\WINDOWS\system32\psohepkw.dll
2007-10-01 19:56:17 75284 --a------ E:\WINDOWS\system32\jklgroey.exe <Not Verified; ; DDC>
2007-09-29 19:56:16 75284 --a------ E:\WINDOWS\system32\ejgrubuq.exe <Not Verified; ; DDC>
2007-09-29 16:17:20 76412 --a------ E:\WINDOWS\system32\sjyicoxy.dll
2007-09-28 19:59:29 159764 --a------ E:\WINDOWS\system32\fbbaphgd.dll
2007-09-28 19:59:29 139264 --a------ E:\WINDOWS\system32\bot007dll.dll
2007-09-28 19:53:26 75284 --a------ E:\WINDOWS\system32\oacuotcf.exe <Not Verified; ; DDC>
2007-09-28 14:16:35 82964 --a------ E:\WINDOWS\system32\swrchtgw.dll
2007-09-28 14:16:34 75284 --a------ E:\WINDOWS\system32\iqgfjfkq.exe <Not Verified; ; DDC>
2007-09-28 01:43:50 75284 --a------ E:\WINDOWS\system32\kcwqwuhj.exe <Not Verified; ; DDC>
2007-09-27 01:43:52 121364 --a------ E:\WINDOWS\system32\dsvdwpox.dll
2007-09-27 01:43:51 75284 --a------ E:\WINDOWS\system32\rvpdsvto.exe <Not Verified; ; DDC>
2007-09-26 01:41:00 75284 --a------ E:\WINDOWS\system32\nrthpspj.exe <Not Verified; ; DDC>
2007-09-25 22:19:04 82964 --a------ E:\WINDOWS\system32\idrqgdir.dll
2007-09-25 22:18:23 75284 --a------ E:\WINDOWS\system32\pvagcrki.exe <Not Verified; ; DDC>
2007-09-25 20:05:42 0 d-------- E:\Programfiler\PartyGaming
2007-09-24 22:18:55 75284 --a------ E:\WINDOWS\system32\nmlveplx.exe <Not Verified; ; DDC>
2007-09-23 22:18:56 75284 --a------ E:\WINDOWS\system32\sjrbrevh.exe <Not Verified; ; DDC>
2007-09-22 22:18:56 121364 --a------ E:\WINDOWS\system32\prgiokyt.dll
2007-09-22 22:18:55 75284 --a------ E:\WINDOWS\system32\uwitueck.exe <Not Verified; ; DDC>
2007-09-22 16:15:55 76412 --a------ E:\WINDOWS\system32\rshdiqsk.dll
2007-09-21 22:15:55 75284 --a------ E:\WINDOWS\system32\gyumvjef.exe <Not Verified; ; DDC>
2007-09-20 22:20:31 82964 --a------ E:\WINDOWS\system32\tknjijuh.dll
2007-09-20 22:17:31 75284 --a------ E:\WINDOWS\system32\mnqliefp.exe <Not Verified; ; DDC>
2007-09-20 19:44:31 0 d-------- E:\Programfiler\Fellesfiler\Teleca Shared
2007-09-19 22:17:39 75284 --a------ E:\WINDOWS\system32\fbltsjnu.exe <Not Verified; ; DDC>
2007-09-18 22:17:41 120852 --a------ E:\WINDOWS\system32\bihdlfer.dll
2007-09-18 22:17:39 75284 --a------ E:\WINDOWS\system32\lngjbgpw.exe <Not Verified; ; DDC>
2007-09-17 22:16:31 125460 --a------ E:\WINDOWS\system32\ugcrutrl.dll
2007-09-17 22:16:29 75284 --a------ E:\WINDOWS\system32\xeyhgjca.exe <Not Verified; ; DDC>
2007-09-16 22:19:29 121364 --a------ E:\WINDOWS\system32\syvaetvb.dll
2007-09-16 22:16:29 75284 --a------ E:\WINDOWS\system32\vdokykql.exe <Not Verified; ; DDC>
2007-09-15 22:16:29 75284 --a------ E:\WINDOWS\system32\dqolynfj.exe <Not Verified; ; DDC>
2007-09-15 16:16:29 76412 --a------ E:\WINDOWS\system32\nngathro.dll
2007-09-14 22:16:29 75284 --a------ E:\WINDOWS\system32\gemdjeuy.exe <Not Verified; ; DDC>
2007-09-13 22:16:02 125460 --a------ E:\WINDOWS\system32\qvjtfxap.dll
2007-09-13 22:16:00 75284 --a------ E:\WINDOWS\system32\jmueauqw.exe <Not Verified; ; DDC>
2007-09-12 22:15:59 75284 --a------ E:\WINDOWS\system32\vmucrgsl.exe <Not Verified; ; DDC>
2007-09-11 22:15:59 75284 --a------ E:\WINDOWS\system32\moqblabe.exe <Not Verified; ; DDC>
2007-09-11 18:38:29 0 d-------- E:\WINDOWS\SxsCaPendDel
2007-09-10 22:15:41 75284 --a------ E:\WINDOWS\system32\chiwebmt.exe <Not Verified; ; DDC>
2007-09-09 22:21:42 121876 --a------ E:\WINDOWS\system32\cpkhyint.dll
2007-09-09 22:15:41 75284 --a------ E:\WINDOWS\system32\vgnkrbbg.exe <Not Verified; ; DDC>
2007-09-08 22:15:39 75284 --a------ E:\WINDOWS\system32\igceuijs.exe <Not Verified; ; DDC>
2007-09-08 16:15:18 76412 --a------ E:\WINDOWS\system32\bxkpyava.dll
2007-09-07 22:14:09 75284 --a------ E:\WINDOWS\system32\vrtnddhf.exe <Not Verified; ; DDC>
2007-09-06 22:19:45 120852 --a------ E:\WINDOWS\system32\roduhyff.dll
2007-09-06 22:16:43 75284 --a------ E:\WINDOWS\system32\gcdbured.exe <Not Verified; ; DDC>
2007-09-06 22:13:55 552400 ---hs---- E:\WINDOWS\system32\hgjlm.bak2
2007-09-05 22:15:36 75284 --a------ E:\WINDOWS\system32\paixxldh.exe <Not Verified; ; DDC>
2007-09-04 22:14:07 0 --a------ E:\WINDOWS\system32\SBRC.dat
2007-09-04 22:14:07 0 --a------ E:\WINDOWS\system32\SBFC.dat
2007-09-04 22:13:43 548190 ---hs---- E:\WINDOWS\system32\hgjlm.bak1
2007-09-04 22:13:35 263220 ---hs---- E:\WINDOWS\system32\mljgh.dll
2007-09-04 19:44:44 75284 --a------ E:\WINDOWS\system32\dqlfnbay.exe <Not Verified; ; DDC>
-- Find3M Report ---------------------------------------------------------------
2007-10-03 21:32:54 0 d-------- E:\Programfiler\MSN Messenger
2007-10-03 08:08:02 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\BitTorrent
2007-09-30 00:17:38 43520 --a------ E:\WINDOWS\system32\CmdLineExt03.dll
2007-09-28 13:18:58 399248 --a------ E:\WINDOWS\system32\perfh014.dat
2007-09-28 13:18:58 68228 --a------ E:\WINDOWS\system32\perfc014.dat
2007-09-24 02:30:06 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\uqm
2007-09-20 19:44:31 0 d-------- E:\Programfiler\Fellesfiler
2007-09-11 18:37:58 0 d--h----- E:\Programfiler\InstallShield Installation Information
2007-09-04 21:33:28 675139 ---hs---- E:\WINDOWS\system32\tttss.ini2
2007-09-04 19:46:22 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\Sunbelt Software
2007-09-04 19:42:55 680567 ---hs---- E:\WINDOWS\system32\tttss.bak2
2007-09-03 19:22:10 75284 --a------ E:\WINDOWS\system32\mjuthuqd.exe <Not Verified; ; DDC>
2007-09-02 16:16:07 75284 --a------ E:\WINDOWS\system32\cxwvcsae.exe <Not Verified; ; DDC>
2007-09-02 16:13:55 688006 ---hs---- E:\WINDOWS\system32\tttss.bak1
2007-09-01 16:21:59 120852 --a------ E:\WINDOWS\system32\jtsknajp.dll
2007-09-01 16:15:56 76412 --a------ E:\WINDOWS\system32\yyyenujt.dll
2007-09-01 16:15:54 75284 --a------ E:\WINDOWS\system32\kqobxyhm.exe <Not Verified; ; DDC>
2007-08-31 19:28:33 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\dvdcss
2007-08-31 16:15:54 75284 --a------ E:\WINDOWS\system32\evcbbhfc.exe <Not Verified; ; DDC>
2007-08-31 15:42:51 46 --a------ E:\WINDOWS\popcinfo.dat
2007-08-30 16:15:54 75284 --a------ E:\WINDOWS\system32\rncmsaun.exe <Not Verified; ; DDC>
2007-08-29 16:15:54 75284 --a------ E:\WINDOWS\system32\csyeqcid.exe <Not Verified; ; DDC>
2007-08-28 16:13:30 75284 --a------ E:\WINDOWS\system32\xjkptnlj.exe <Not Verified; ; DDC>
2007-08-28 16:06:25 75284 --a------ E:\WINDOWS\system32\vijpidqq.exe <Not Verified; ; DDC>
2007-08-28 00:41:59 125460 --a------ E:\WINDOWS\system32\qkcrgpej.dll
2007-08-28 00:39:33 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\Skype
2007-08-27 03:37:38 125460 --a------ E:\WINDOWS\system32\ofhbyjml.dll
2007-08-26 20:22:18 125460 --a------ E:\WINDOWS\system32\okfktosj.dll
2007-08-25 16:11:19 125460 --a------ E:\WINDOWS\system32\fntoentc.dll
2007-08-25 16:08:19 76412 --a------ E:\WINDOWS\system32\qdtthdtn.dll
2007-08-25 16:02:25 124436 --a------ E:\WINDOWS\system32\mmvsfhwu.dll
2007-08-25 07:18:43 125460 --a------ E:\WINDOWS\system32\cjqxlgwl.dll
2007-08-23 22:04:02 76412 --a------ E:\WINDOWS\system32\awjwvrya.dll
2007-08-23 18:46:00 125460 --a------ E:\WINDOWS\system32\sfrhrjtq.dll
2007-08-19 18:46:01 121364 --a------ E:\WINDOWS\system32\nnovnfgg.dll
2007-08-19 15:14:26 118784 --a------ E:\WINDOWS\system32\SeismoSaver.scr <Not Verified; NuGardt Software; SeismoSaver 2>
2007-08-16 22:07:23 125460 --a------ E:\WINDOWS\system32\mdvxqeww.dll
2007-08-16 22:04:23 76412 --a------ E:\WINDOWS\system32\abytaqwy.dll
2007-08-16 22:01:31 75284 --a------ E:\WINDOWS\system32\ltdlsypp.exe <Not Verified; ; DDC>
2007-08-15 23:48:42 125460 --a------ E:\WINDOWS\system32\fegrlpdi.dll
2007-08-15 23:48:13 75284 --a------ E:\WINDOWS\system32\mupklktv.exe <Not Verified; ; DDC>
2007-08-14 23:45:59 75284 --a------ E:\WINDOWS\system32\vfwpshhd.exe <Not Verified; ; DDC>
2007-08-14 19:45:16 75284 --a------ E:\WINDOWS\system32\dpjxyycr.exe <Not Verified; ; DDC>
2007-08-14 15:40:11 125460 --a------ E:\WINDOWS\system32\xmdiclew.dll
2007-08-14 15:37:14 75284 --a------ E:\WINDOWS\system32\cucegmbx.exe <Not Verified; ; DDC>
2007-08-14 01:50:36 125460 --a------ E:\WINDOWS\system32\pentanuc.dll
2007-08-14 01:47:35 75284 --a------ E:\WINDOWS\system32\ptonhjbe.exe <Not Verified; ; DDC>
2007-08-13 02:15:17 125460 --a------ E:\WINDOWS\system32\kxdqmmfw.dll
2007-08-13 02:12:51 75284 --a------ E:\WINDOWS\system32\kkgypduj.exe <Not Verified; ; DDC>
2007-08-12 22:25:24 76412 --a------ E:\WINDOWS\system32\myxvctpw.dll
2007-08-12 07:40:32 75284 --a------ E:\WINDOWS\system32\tytdcaxy.exe <Not Verified; ; DDC>
2007-08-12 00:25:41 125460 --a------ E:\WINDOWS\system32\rjwmrsxw.dll
2007-08-12 00:25:40 75284 --a------ E:\WINDOWS\system32\rtitualw.exe <Not Verified; ; DDC>
2007-08-11 00:28:43 120852 --a------ E:\WINDOWS\system32\gnwngprs.dll
2007-08-11 00:25:41 75284 --a------ E:\WINDOWS\system32\wkyprsqk.exe <Not Verified; ; DDC>
2007-08-10 19:06:31 35546 --a------ E:\WINDOWS\DIIUnin.dat
2007-08-10 18:52:17 21840 --a------ E:\WINDOWS\system32\SIntfNT.dll
2007-08-10 18:52:17 17212 --a------ E:\WINDOWS\system32\SIntf32.dll
2007-08-10 18:52:17 12067 --a------ E:\WINDOWS\system32\SIntf16.dll
2007-08-10 18:43:06 2829 --a------ E:\WINDOWS\DIIUnin.pif
2007-08-10 18:43:06 94208 --a------ E:\WINDOWS\DIIUnin.exe <Not Verified; Blizzard Entertainment; Diablo II Uninstaller>
2007-08-10 00:23:35 75284 --a------ E:\WINDOWS\system32\hhqpckqj.exe <Not Verified; ; DDC>
2007-08-07 08:51:39 66068 --a------ E:\WINDOWS\system32\qwbtpbal.exe
2007-08-07 08:48:58 66068 --a------ E:\WINDOWS\system32\mlndeiei.exe
2007-08-07 01:21:13 66068 --a------ E:\WINDOWS\system32\sbyrixpf.exe
2007-08-06 01:21:15 120852 --a------ E:\WINDOWS\system32\dabolmqx.dll
2007-08-06 01:21:13 66068 --a------ E:\WINDOWS\system32\grrurwrs.exe
2007-08-05 22:24:14 76412 --a------ E:\WINDOWS\system32\eunhfktc.dll
2007-08-05 01:21:13 66068 --a------ E:\WINDOWS\system32\lvkdphdh.exe
2007-08-04 01:18:19 66068 --a------ E:\WINDOWS\system32\tvgmbxkg.exe
2007-08-04 01:15:35 66068 --a------ E:\WINDOWS\system32\mqkpktgd.exe
2007-08-03 01:15:35 125460 --a------ E:\WINDOWS\system32\eiqlildg.dll
2007-08-03 01:13:02 66068 --a------ E:\WINDOWS\system32\kxtatacj.exe
2007-08-03 00:49:53 66068 --a------ E:\WINDOWS\system32\gplwegek.exe
2007-08-01 22:18:14 66068 --a------ E:\WINDOWS\system32\bjsjnxqe.exe
2007-07-31 22:18:14 66068 --a------ E:\WINDOWS\system32\ktrodfkv.exe
2007-07-30 22:18:14 66068 --a------ E:\WINDOWS\system32\psucbaht.exe
2007-07-29 22:26:02 69140 --a------ E:\WINDOWS\system32\trxxmaxe.dll
2007-07-29 22:23:02 76412 --a------ E:\WINDOWS\system32\ykipwxms.dll
2007-07-29 22:20:02 66068 --a------ E:\WINDOWS\system32\hrnaftqh.exe
2007-07-29 22:17:29 66068 --a------ E:\WINDOWS\system32\cphtrkkx.exe
2007-07-25 03:08:33 66580 --a------ E:\WINDOWS\system32\kdahqcqp.dll
2007-07-25 03:02:45 66068 --a------ E:\WINDOWS\system32\mpypqhyw.exe
2007-07-24 17:20:35 66580 --a------ E:\WINDOWS\system32\opyecmah.dll
2007-07-24 17:20:29 66068 --a------ E:\WINDOWS\system32\lxxeahxx.exe
2007-07-24 17:20:29 125972 --a------ E:\WINDOWS\system32\cewcmdue.dll
2007-07-23 17:26:28 66580 --a------ E:\WINDOWS\system32\pwomddhf.dll
2007-07-23 17:20:28 66068 --a------ E:\WINDOWS\system32\mlmkdanc.exe
2007-07-22 17:27:09 66580 --a------ E:\WINDOWS\system32\eyfjvfyx.dll
2007-07-22 17:21:09 66068 --a------ E:\WINDOWS\system32\veoqhfns.exe
2007-07-21 04:27:10 66580 --a------ E:\WINDOWS\system32\xdwoqtrl.dll
2007-07-21 04:24:12 125460 --a------ E:\WINDOWS\system32\rhxlmbef.dll
2007-07-21 04:24:09 66068 --a------ E:\WINDOWS\system32\hlpyncvb.exe
2007-07-20 18:36:09 76412 --a------ E:\WINDOWS\system32\tgujjenv.dll
2007-07-20 04:27:09 66580 --a------ E:\WINDOWS\system32\ldvlldnr.dll
2007-07-20 04:24:09 66068 --a------ E:\WINDOWS\system32\pbxamtgv.exe
2007-07-19 04:24:13 66580 --a------ E:\WINDOWS\system32\fgitjwaw.dll
2007-07-19 04:24:12 66068 --a------ E:\WINDOWS\system32\cgfbwpkr.exe
2007-07-18 04:24:14 66580 --a------ E:\WINDOWS\system32\vfscxrea.dll
2007-07-18 04:21:16 66068 --a------ E:\WINDOWS\system32\ekvwtqvy.exe
2007-07-17 17:05:05 66580 --a------ E:\WINDOWS\system32\xqwjmgsj.dll
2007-07-17 17:05:01 124436 --a------ E:\WINDOWS\system32\iqwcvnjv.dll
2007-07-17 17:05:00 66068 --a------ E:\WINDOWS\system32\aoytdhdf.exe
2007-07-17 17:02:00 66068 --a------ E:\WINDOWS\system32\fhypxkha.exe
2007-07-17 06:14:27 66580 --a------ E:\WINDOWS\system32\tdjpsjda.dll
2007-07-17 06:14:26 66068 --a------ E:\WINDOWS\system32\fdmgkpnq.exe
2007-07-16 06:14:31 66580 --a------ E:\WINDOWS\system32\wimuwtfh.dll
2007-07-16 06:14:27 124436 --a------ E:\WINDOWS\system32\qtmjtjvx.dll
2007-07-16 06:11:42 66068 --a------ E:\WINDOWS\system32\ohjvwunl.exe
2007-07-16 02:34:42 124436 --a------ E:\WINDOWS\system32\xywprssm.dll
2007-07-16 02:31:41 66580 --a------ E:\WINDOWS\system32\rkeefaot.dll
2007-07-16 02:29:59 66068 --a------ E:\WINDOWS\system32\eqxdvwbi.exe
2007-07-15 14:45:45 66580 --a------ E:\WINDOWS\system32\edlnwxgr.dll
2007-07-15 14:42:46 124436 --a------ E:\WINDOWS\system32\rdcllipk.dll
2007-07-15 14:39:44 66068 --a------ E:\WINDOWS\system32\oobdhlig.exe
2007-07-14 15:47:08 737280 --a------ E:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2007-07-14 15:32:28 528 -r-hs---- E:\WINDOWS\egirllic151
2007-07-14 14:39:47 66580 --a------ E:\WINDOWS\system32\snhcduqj.dll
2007-07-14 14:39:45 66068 --a------ E:\WINDOWS\system32\dqwhtill.exe
2007-07-13 18:36:44 76412 --a------ E:\WINDOWS\system32\hyydlxao.dll
2007-07-13 14:42:44 66580 --a------ E:\WINDOWS\system32\rcnuxdhn.dll
2007-07-13 14:39:44 66068 --a------ E:\WINDOWS\system32\lmvfamku.exe
2007-07-12 14:38:44 66580 --a------ E:\WINDOWS\system32\uvrmjwvj.dll
2007-07-12 14:38:40 66068 --a------ E:\WINDOWS\system32\djqiwoev.exe
2007-07-08 18:32:27 50708 --a------ E:\WINDOWS\system32\elwkgeon.exe <Not Verified; ; DDC>
2007-07-07 18:32:28 50708 --a------ E:\WINDOWS\system32\qeqccmvv.exe <Not Verified; ; DDC>
2007-07-06 18:36:05 76412 --a------ E:\WINDOWS\system32\kryjajhg.dll
2007-07-06 18:30:18 50708 --a------ E:\WINDOWS\system32\rqplvuua.exe <Not Verified; ; DDC>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02633FD6-4FBE-47B1-8966-7C223969A25B}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{709AFF26-6BB0-4AD3-A3A3-1286592465D6}]
05/26/2007 04:00 AM 29206 --a------ E:\WINDOWS\system32\nnnomml.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9B5CFE0B-BE3B-4552-811D-84539C0DCFA5}]
09/04/2007 10:13 PM 263220 ---hs---- E:\WINDOWS\system32\mljgh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1}]
07/29/2007 10:26 PM 69140 --a------ E:\WINDOWS\system32\trxxmaxe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E980DD43-BEDE-46DD-BC03-BB7B85544898}]
10/02/2007 12:57 AM 121364 --a------ E:\WINDOWS\system32\ukwhuvtf.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="H:\Prog\Java\bin\jusched.exe" [07/12/2007 04:00 AM]
"LVCOMSX"="E:\WINDOWS\system32\LVCOMSX.EXE" [10/08/2004 11:52 AM]
"NvCplDaemon"="E:\WINDOWS\system32\NvCpl.dll" [08/11/2006 09:43 PM]
"nwiz"="nwiz.exe" [08/11/2006 09:43 PM E:\WINDOWS\system32\nwiz.exe]
"Smapp"="E:\Programfiler\Analog Devices\SoundMAX\SMTray.exe" [05/05/2003 08:57 AM]
"QuickTime Task"="E:\Programfiler\QuickTime\qttask.exe" [04/30/2006 01:05 PM]
"PKR Pal"="H:\Sindre\Spill\PKR\pkrpal.exe" [09/19/2007 12:18 AM]
"PWRISOVM.EXE"="H:\Prog\PowerISO\PWRISOVM.EXE" [08/07/2007 02:05 AM]
"SearchIndexer"="E:\WINDOWS\system32\ymqwfikn.dll" [10/03/2007 09:33 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="E:\Programfiler\MSN Messenger\MsnMsgr.exe" [01/19/2007 01:54 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"*CmaudioMon"=rundll32.exe bot007dll.dll,_EntryPoint@16
E:\Documents and Settings\Per_Killer\Start-meny\Programmer\Oppstart\
Adobe Gamma.lnk - E:\Programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe [12:00:00 AM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{709AFF26-6BB0-4AD3-A3A3-1286592465D6}"= E:\WINDOWS\system32\nnnomml.dll [05/26/2007 04:00 AM 29206]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljgh]
E:\WINDOWS\system32\mljgh.dll 09/04/2007 10:13 PM 263220 E:\WINDOWS\system32\mljgh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnomml]
nnnomml.dll 05/26/2007 04:00 AM 29206 E:\WINDOWS\system32\nnnomml.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssttt]
E:\WINDOWS\system32\ssttt.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CookiePatrol]
C:\Prog\PestPatrol\CookiePatrol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"C:\Prog\D-Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
C:\Prog\Internet Download Manager\IDMan.exe /onboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Prog\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Prog\Logitech\Video\ManifestEngine.exe boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Prog\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Prog\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"E:\Programfiler\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PestPatrol Control Center]
C:\Prog\PestPatrol\PPControl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPMemCheck]
C:\Prog\PestPatrol\PPMemCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"E:\Programfiler\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
E:\Programfiler\VIA\RAID\raid_tool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
E:\Sindre\Spill\Steam\\Steam.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Macromedia Licensing Service"=3 (0x3)
"iPodService"=3 (0x3)
"IDriverT"=3 (0x3)
"Bonjour Service"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\SETUP.EXE
-- End of Deckard's System Scanner: finished at 2007-10-04 02:33:18 ------------
I've been having some problems with my computer and I've always somehow managed to work my way around the issues spyware/malware etc. have created but lately it's been getting out of hand.. Some time ago I got a virus or something that made the entire tab under "Processes" dissapear. So I could not see process-names in the task-manager. I have re-installed XP but this problem persists. I have been using a different application to monitor and handle processes.
The problem now is the constant pop-ups generated from this fake anti-virus program calling itself "Anti Virus Pro 2007" or something.. It pops up with fake commercials, and even attach itself into other explorer-windows while I view other pages.
As popups and messageboxes keep popping up, I close them, but after a while windows will open a messagebox telling me "Buffer overrun detected in e:\Windows\system32\explorer.exe" (or \\windows\explorer.exe I don't remember really but you get the idea) and explorer.exe will be terminated, sometimes taking some internet explorer windows along with it, other times explorer.exe just starts up again and all my windows remain.
I used to have Norton but was forced to remove it as it was sucking up all my CPU. It rendered my computer useless, as I mainly use it for gaming.
I've also experienced having the connection between me and my modem broken while beeing on the internet, and I don't know if my computer actually is offline or if -I'm- just offline.. The LAN-connection won't detect my modem and I can't even find it by pinging it.
I have been trough Step 1 without finding anything I could remove in control-panel.
The panda online search take hours if not days to finish, as it slows down severly after a certain time.. I have tried acouple of times but before it finish a popup or an error will close the browser window :/
EDIT: I forgot to mention.. I have tried to follow acouple of solutions I saw you guys giving people with similiar problems as I had, and searching for malware and stuff it did find some infected dll-files in my system32 folder and other windows-folders. I deleted afew but something called nnommmll.dll or something was attached to winlogon.exe and therefore I couldn't delete it. The other files came back after my computer crashed anyway though x.x
I'll now paste the logfile generated by dss.exe
----------------------------------------------------
Deckard's System Scanner v20070905.67
Run by Per_Killer on 2007-10-04 02:29:20
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 4 Restore Point(s) --
4: 2007-10-04 00:29:26 UTC - RP203 - Deckard's System Scanner Restore Point
3: 2007-10-03 17:36:54 UTC - RP202 - Kontrollpunkt for system
2: 2007-10-02 05:58:08 UTC - RP201 - Kontrollpunkt for system
1: 2007-09-29 10:08:40 UTC - RP200 - Kontrollpunkt for system
Backed up registry hives.
Performed disk cleanup.
System Drive E: has 10.05 GiB (less than 15%) free.
-- HijackThis (run as Per_Killer.exe) ------------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-10-04 02:32:11
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Running processes:
E:\WINDOWS\system32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\CTSVCCDA.EXE
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\PnkBstrA.exe
E:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\wscntfy.exe
H:\Prog\Java\bin\jusched.exe
E:\WINDOWS\system32\LVCOMSX.EXE
E:\Programfiler\Analog Devices\SoundMAX\SMTray.exe
E:\Programfiler\MSN Messenger\msnmsgr.exe
E:\Programfiler\MSN Messenger\usnsvc.exe
C:\Prog\Mirc\mirc.exe
E:\WINDOWS\explorer.exe
H:\Sindre\Spill\Online\Dark Ages\DarkAges.exe
E:\Programfiler\iPod\bin\iPodService.exe
E:\Programfiler\Internet Explorer\iexplore.exe
E:\Documents and Settings\Per_Killer\Skrivebord\FIX\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.no/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - H:\Prog\SnagIt\SnagItBHO.dll
O2 - BHO: (no name) - {02633FD6-4FBE-47B1-8966-7C223969A25B} - (no file)
O2 - BHO: (no name) - {709AFF26-6BB0-4AD3-A3A3-1286592465D6} - E:\WINDOWS\system32\nnnomml.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Prog\Java\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9B5CFE0B-BE3B-4552-811D-84539C0DCFA5} - E:\WINDOWS\system32\mljgh.dll
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - E:\WINDOWS\system32\trxxmaxe.dll
O2 - BHO: (no name) - {E980DD43-BEDE-46DD-BC03-BB7B85544898} - E:\WINDOWS\system32\ukwhuvtf.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - H:\Prog\SnagIt\SnagItIEAddin.dll
O4 - HKEY_LOCAL_MACHINE\..\Run: [SunJavaUpdateSched] "H:\Prog\Java\bin\jusched.exe"
O4 - HKEY_LOCAL_MACHINE\..\Run: [LVCOMSX] E:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKEY_LOCAL_MACHINE\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKEY_LOCAL_MACHINE\..\Run: [nwiz] nwiz.exe /install
O4 - HKEY_LOCAL_MACHINE\..\Run: [Smapp] E:\Programfiler\Analog Devices\SoundMAX\SMTray.exe
O4 - HKEY_LOCAL_MACHINE\..\Run: [QuickTime Task] "E:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKEY_LOCAL_MACHINE\..\Run: [PKR Pal] "H:\Sindre\Spill\PKR\pkrpal.exe" -osboot
O4 - HKEY_LOCAL_MACHINE\..\Run: [PWRISOVM.EXE] H:\Prog\PowerISO\PWRISOVM.EXE
O4 - HKEY_LOCAL_MACHINE\..\Run: [SearchIndexer] rundll32.exe "E:\WINDOWS\system32\ymqwfikn.dll",sitypnow
O4 - HKEY_LOCAL_MACHINE\..\RunOnce: [*CmaudioMon] rundll32.exe bot007dll.dll,_EntryPoint@16
O4 - HKCU\..\Run: [MsnMsgr] "E:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = E:\Programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Registration .LNK = H:\Sindre\Spill\Dark Messiah\Dark Messiah of Might and Magic\RegistrationReminder.exe
O8 - Extra context menu item: Download All Links with IDM - C:\Prog\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Prog\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Prog\Java\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Prog\Java\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - E:\Documents and Settings\Per_Killer\Start-meny\Programmer\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - E:\Documents and Settings\Per_Killer\Start-meny\Programmer\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {44226DFF-747E-4edc-B30C-78752E50CD0C} - (file missing)
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - H:\Sindre\Spill\PokerGames\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - H:\Sindre\Spill\PokerGames\Titan Poker\casino.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\Programfiler\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\Programfiler\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programfiler\Messenger\msmsgs.exe
O16 - DPF: {0A50726E-51A2-42BB-8392-98F050C40A10} (SkillJamLoader Class) - http://rcade.skilljam.com/ssp/SkillJamLoader.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) - http://www.powerflasher.de/plugin/powerres.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://www.cherrytreeinn.com:8080/kxhcm10.ocx
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab Class) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - E:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - E:\Programfiler\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - E:\Programfiler\MSN Messenger\msgrapp.8.1.0178.00.dll
O20 - Winlogon Notify: AtiExtEvent - E:\WINDOWS\system32\
O20 - Winlogon Notify: mljgh - E:\WINDOWS\system32\mljgh.dll
O20 - Winlogon Notify: nnnomml - E:\WINDOWS\system32\nnnomml.dll
O20 - Winlogon Notify: ssttt - E:\WINDOWS\system32\ssttt.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - "E:\Programfiler\Fellesfiler\Adobe Systems Shared\Service\Adobelmsvc.exe"
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - E:\WINDOWS\system32\CTSVCCDA.EXE
O23 - Service: DomainService - Unknown owner - E:\WINDOWS\system32\uflpuqca.exe /service
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "E:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe"
O23 - Service: iPodService - Apple Computer, Inc. - E:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - "E:\Programfiler\Fellesfiler\Macromedia Shared\Service\Macromedia Licensing.exe"
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
-- HijackThis Fixed Entries (H:\Prog\HIJACK~1\backups\) ------------------------
backup-20061130-055756-706 O2 - BHO: °Ù¶È³¬¼¶ËÑ°Ô - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - E:\Progra~1\Baidu\bar\BaiDuBar.dll
backup-20061130-055840-122 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Prog\Java\jre1.5.0_06\bin\ssv.dll
backup-20061130-055840-766 O3 - Toolbar: (no name) - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - (no file)
backup-20061130-055840-841 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Prog\Spybot - Search & Destroy\SDHelper.dll
backup-20061130-055850-443 O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Prog\Internet Download Manager\IDMIECC.dll
backup-20061130-055913-313 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Prog\Adobe Reader\Reader\ActiveX\AcroIEHelper.dll
backup-20061130-055937-730 R3 - Default URLSearchHook is missing
backup-20061130-060029-107 O8 - Extra context menu item: °Ù¶È-ËÑË÷ÐÂÎÅ - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUNEWS.HTM
backup-20061130-060029-200 O8 - Extra context menu item: °Ù¶È-ËÑË÷ͼƬ - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUIMG.HTM
backup-20061130-060029-247 O8 - Extra context menu item: °Ù¶È-ËÑË÷¸è´Ê - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDULYRIC.HTM
backup-20061130-060029-510 O8 - Extra context menu item: °Ù¶È-ËÑË÷MP3 - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUMP3.HTM
backup-20061130-060029-755 O8 - Extra context menu item: °Ù¶È-´ÊµäËÑË÷ - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDU_DIC.HTM
backup-20061130-060029-770 O8 - Extra context menu item: °Ù¶È-ËÑË÷Ìù°É - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUPOST.HTM
backup-20061130-060029-832 O8 - Extra context menu item: °Ù¶È-ËÑË÷ÍøÒ³ - res://E:\Progra~1\Baidu\bar\BaiDuBar.dll/BAIDUSEARCH.HTM
backup-20061130-060102-266 O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Sindre\Spill\PokerGames\PartyPoker\PartyPoker\RunApp.exe
backup-20061130-060102-369 O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - E:\Sindre\Spill\POKER\Poker.com\poker.exe
backup-20061130-060102-390 O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Sindre\Spill\PokerGames\PartyPoker\PartyPoker\RunApp.exe
backup-20061130-060102-691 O9 - Extra button: Noble Poker - {B723B1B8-9788-4684-ADA7-D1DB02E1D516} - E:\Sindre\Spill\POKER\Noble Poker\casino.exe
backup-20061130-060102-838 O9 - Extra button: CDpoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - E:\Sindre\Spill\POKER\CDpoker\casino.exe
backup-20061130-060103-144 O9 - Extra 'Tools' menuitem: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - E:\Documents and Settings\All Users\Start-meny\Programmer\Absolute Poker\Absolute Poker.lnk (file missing)
backup-20061130-060103-568 O9 - Extra button: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - E:\Documents and Settings\All Users\Start-meny\Programmer\Absolute Poker\Absolute Poker.lnk (file missing)
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - e:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - e:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - e:\windows\system32\drivers\sfvfs02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 SCDEmu - e:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R2 CdaD10BA - e:\windows\system32\drivers\cdad10ba.sys <Not Verified; Macrovision Europe Ltd; Security Windows NT>
R2 ithsgt - e:\windows\system32\drivers\ithsgt.sys
R2 lilsgt - e:\windows\system32\drivers\lilsgt.sys
R3 scskusbf (USB SCSK Filter Driver Service) - e:\windows\system32\drivers\scskusbf.sys <Not Verified; SoftCamp; SCSKUSBf 4.0.1.6>
R3 scskusbs (USB SCSK Driver Service) - e:\windows\system32\drivers\scskusbs.sys <Not Verified; SoftCamp; SCSKUSBs 4.0.1.6>
R3 Tetris (Tetris driver) - e:\windows\system32\drivers\tetris.sys
S2 zntport (NTPort Library Driver) - e:\windows\system32\zntport.sys (file missing)
S3 EagleNT - e:\windows\system32\drivers\eaglent.sys (file missing)
S3 FreshIO - h:\prog\freshdiagnose\freshio.sys
S3 KLIF - c:\prog\pctool~1\klif.sys (file missing)
S3 scsk4 (SCSK4 Driver Service) - e:\windows\system32\drivers\scsk4.sys <Not Verified; SoftCamp Co., Inc.; SoftCamp Secure KeyStroke>
S3 XDva004 - e:\windows\system32\xdva004.sys (file missing)
S3 XTrapD12 - e:\windows\system32\xtrapd12.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 DomainService - e:\windows\system32\uflpuqca.exe /service (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2007-09-04 and 2007-10-04 -----------------------------
2007-10-03 21:39:22 76412 --a------ E:\WINDOWS\system32\lgdlbcwi.dll
2007-10-03 21:33:10 82964 --a------ E:\WINDOWS\system32\ymqwfikn.dll
2007-10-03 21:30:27 75284 --a------ E:\WINDOWS\system32\ltridbwa.exe <Not Verified; ; DDC>
2007-10-03 21:23:06 0 d-------- E:\WINDOWS\system32\ActiveScan
2007-10-03 21:23:04 0 d-------- E:\WINDOWS\LastGood
2007-10-03 17:56:26 82964 --a------ E:\WINDOWS\system32\giypnwod.dll
2007-10-03 17:53:34 75284 --a------ E:\WINDOWS\system32\fbyghkdt.exe <Not Verified; ; DDC>
2007-10-03 16:57:58 82964 -----n--- E:\WINDOWS\system32\dnmtpwpx.dll
2007-10-03 16:55:08 75284 --a------ E:\WINDOWS\system32\tdedrhik.exe <Not Verified; ; DDC>
2007-10-03 16:15:16 82964 --a------ E:\WINDOWS\system32\vaipaolq.dll
2007-10-03 16:12:28 75284 --a------ E:\WINDOWS\system32\kfcxdptg.exe <Not Verified; ; DDC>
2007-10-03 15:40:03 543656 ---hs---- E:\WINDOWS\system32\hgjlm.ini2
2007-10-02 22:28:47 82964 --a------ E:\WINDOWS\system32\itscdfva.dll
2007-10-02 22:25:57 75284 --a------ E:\WINDOWS\system32\cpvhguli.exe <Not Verified; ; DDC>
2007-10-02 22:23:06 75284 --a------ E:\WINDOWS\system32\iuhsdtss.exe <Not Verified; ; DDC>
2007-10-02 19:22:36 82964 --a------ E:\WINDOWS\system32\qkglxptl.dll
2007-10-02 19:19:36 75284 --a------ E:\WINDOWS\system32\kvqigrpj.exe <Not Verified; ; DDC>
2007-10-02 19:16:37 75284 --a------ E:\WINDOWS\system32\hqngeotd.exe <Not Verified; ; DDC>
2007-10-02 18:58:01 82964 --a------ E:\WINDOWS\system32\abwlxwrg.dll
2007-10-02 18:58:00 75284 --a------ E:\WINDOWS\system32\fhbdfhbp.exe <Not Verified; ; DDC>
2007-10-02 18:53:13 82964 --a------ E:\WINDOWS\system32\xydvsbfo.dll
2007-10-02 18:50:25 75284 --a------ E:\WINDOWS\system32\msvrjkxu.exe <Not Verified; ; DDC>
2007-10-02 18:47:34 75284 --a------ E:\WINDOWS\system32\wjffaynk.exe <Not Verified; ; DDC>
2007-10-02 18:23:06 82964 --a------ E:\WINDOWS\system32\ehhqxite.dll
2007-10-02 18:05:56 75284 --a------ E:\WINDOWS\system32\nykvengt.exe <Not Verified; ; DDC>
2007-10-02 17:16:23 75284 --a------ E:\WINDOWS\system32\kfoheveo.exe <Not Verified; ; DDC>
2007-10-02 17:13:24 75284 --a------ E:\WINDOWS\system32\idrunlti.exe <Not Verified; ; DDC>
2007-10-02 16:26:16 82964 --a------ E:\WINDOWS\system32\sbqqaysh.dll
2007-10-02 16:23:05 75284 --a------ E:\WINDOWS\system32\liugktpa.exe <Not Verified; ; DDC>
2007-10-02 15:50:00 82964 --a------ E:\WINDOWS\system32\ymdknvym.dll
2007-10-02 15:49:59 75284 --a------ E:\WINDOWS\system32\kplrlyop.exe <Not Verified; ; DDC>
2007-10-02 15:46:59 75284 --a------ E:\WINDOWS\system32\liildpvt.exe <Not Verified; ; DDC>
2007-10-02 07:43:56 75284 --a------ E:\WINDOWS\system32\oqjxmygl.exe <Not Verified; ; DDC>
2007-10-02 07:40:57 75284 --a------ E:\WINDOWS\system32\leemlqxm.exe <Not Verified; ; DDC>
2007-10-02 07:21:28 82964 --a------ E:\WINDOWS\system32\cmaudyql.dll
2007-10-02 07:20:30 314368 --a------ E:\WINDOWS\uninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2007-10-02 07:18:28 75284 --a------ E:\WINDOWS\system32\oxbpsifa.exe <Not Verified; ; DDC>
2007-10-02 07:15:35 75284 --a------ E:\WINDOWS\system32\otgambbm.exe <Not Verified; ; DDC>
2007-10-02 02:20:15 75284 --a------ E:\WINDOWS\system32\pjfgbnoj.exe <Not Verified; ; DDC>
2007-10-02 01:10:14 82964 --a------ E:\WINDOWS\system32\rwpkrfhf.dll
2007-10-02 01:04:20 75284 --a------ E:\WINDOWS\system32\smhrxgch.exe <Not Verified; ; DDC>
2007-10-02 01:00:42 82964 --a------ E:\WINDOWS\system32\vrpifpcc.dll
2007-10-02 00:57:43 121364 --a------ E:\WINDOWS\system32\ukwhuvtf.dll
2007-10-02 00:57:41 75284 --a------ E:\WINDOWS\system32\powoncmw.exe <Not Verified; ; DDC>
2007-10-02 00:54:42 75284 --a------ E:\WINDOWS\system32\pbggysns.exe <Not Verified; ; DDC>
2007-10-02 00:42:17 82964 --a------ E:\WINDOWS\system32\lwnenddr.dll
2007-10-02 00:36:25 75284 --a------ E:\WINDOWS\system32\onburapy.exe <Not Verified; ; DDC>
2007-10-02 00:02:59 82964 --a------ E:\WINDOWS\system32\eycqhfep.dll
2007-10-01 23:54:14 75284 --a------ E:\WINDOWS\system32\fxxhumhy.exe <Not Verified; ; DDC>
2007-10-01 19:56:18 82964 --a------ E:\WINDOWS\system32\psohepkw.dll
2007-10-01 19:56:17 75284 --a------ E:\WINDOWS\system32\jklgroey.exe <Not Verified; ; DDC>
2007-09-29 19:56:16 75284 --a------ E:\WINDOWS\system32\ejgrubuq.exe <Not Verified; ; DDC>
2007-09-29 16:17:20 76412 --a------ E:\WINDOWS\system32\sjyicoxy.dll
2007-09-28 19:59:29 159764 --a------ E:\WINDOWS\system32\fbbaphgd.dll
2007-09-28 19:59:29 139264 --a------ E:\WINDOWS\system32\bot007dll.dll
2007-09-28 19:53:26 75284 --a------ E:\WINDOWS\system32\oacuotcf.exe <Not Verified; ; DDC>
2007-09-28 14:16:35 82964 --a------ E:\WINDOWS\system32\swrchtgw.dll
2007-09-28 14:16:34 75284 --a------ E:\WINDOWS\system32\iqgfjfkq.exe <Not Verified; ; DDC>
2007-09-28 01:43:50 75284 --a------ E:\WINDOWS\system32\kcwqwuhj.exe <Not Verified; ; DDC>
2007-09-27 01:43:52 121364 --a------ E:\WINDOWS\system32\dsvdwpox.dll
2007-09-27 01:43:51 75284 --a------ E:\WINDOWS\system32\rvpdsvto.exe <Not Verified; ; DDC>
2007-09-26 01:41:00 75284 --a------ E:\WINDOWS\system32\nrthpspj.exe <Not Verified; ; DDC>
2007-09-25 22:19:04 82964 --a------ E:\WINDOWS\system32\idrqgdir.dll
2007-09-25 22:18:23 75284 --a------ E:\WINDOWS\system32\pvagcrki.exe <Not Verified; ; DDC>
2007-09-25 20:05:42 0 d-------- E:\Programfiler\PartyGaming
2007-09-24 22:18:55 75284 --a------ E:\WINDOWS\system32\nmlveplx.exe <Not Verified; ; DDC>
2007-09-23 22:18:56 75284 --a------ E:\WINDOWS\system32\sjrbrevh.exe <Not Verified; ; DDC>
2007-09-22 22:18:56 121364 --a------ E:\WINDOWS\system32\prgiokyt.dll
2007-09-22 22:18:55 75284 --a------ E:\WINDOWS\system32\uwitueck.exe <Not Verified; ; DDC>
2007-09-22 16:15:55 76412 --a------ E:\WINDOWS\system32\rshdiqsk.dll
2007-09-21 22:15:55 75284 --a------ E:\WINDOWS\system32\gyumvjef.exe <Not Verified; ; DDC>
2007-09-20 22:20:31 82964 --a------ E:\WINDOWS\system32\tknjijuh.dll
2007-09-20 22:17:31 75284 --a------ E:\WINDOWS\system32\mnqliefp.exe <Not Verified; ; DDC>
2007-09-20 19:44:31 0 d-------- E:\Programfiler\Fellesfiler\Teleca Shared
2007-09-19 22:17:39 75284 --a------ E:\WINDOWS\system32\fbltsjnu.exe <Not Verified; ; DDC>
2007-09-18 22:17:41 120852 --a------ E:\WINDOWS\system32\bihdlfer.dll
2007-09-18 22:17:39 75284 --a------ E:\WINDOWS\system32\lngjbgpw.exe <Not Verified; ; DDC>
2007-09-17 22:16:31 125460 --a------ E:\WINDOWS\system32\ugcrutrl.dll
2007-09-17 22:16:29 75284 --a------ E:\WINDOWS\system32\xeyhgjca.exe <Not Verified; ; DDC>
2007-09-16 22:19:29 121364 --a------ E:\WINDOWS\system32\syvaetvb.dll
2007-09-16 22:16:29 75284 --a------ E:\WINDOWS\system32\vdokykql.exe <Not Verified; ; DDC>
2007-09-15 22:16:29 75284 --a------ E:\WINDOWS\system32\dqolynfj.exe <Not Verified; ; DDC>
2007-09-15 16:16:29 76412 --a------ E:\WINDOWS\system32\nngathro.dll
2007-09-14 22:16:29 75284 --a------ E:\WINDOWS\system32\gemdjeuy.exe <Not Verified; ; DDC>
2007-09-13 22:16:02 125460 --a------ E:\WINDOWS\system32\qvjtfxap.dll
2007-09-13 22:16:00 75284 --a------ E:\WINDOWS\system32\jmueauqw.exe <Not Verified; ; DDC>
2007-09-12 22:15:59 75284 --a------ E:\WINDOWS\system32\vmucrgsl.exe <Not Verified; ; DDC>
2007-09-11 22:15:59 75284 --a------ E:\WINDOWS\system32\moqblabe.exe <Not Verified; ; DDC>
2007-09-11 18:38:29 0 d-------- E:\WINDOWS\SxsCaPendDel
2007-09-10 22:15:41 75284 --a------ E:\WINDOWS\system32\chiwebmt.exe <Not Verified; ; DDC>
2007-09-09 22:21:42 121876 --a------ E:\WINDOWS\system32\cpkhyint.dll
2007-09-09 22:15:41 75284 --a------ E:\WINDOWS\system32\vgnkrbbg.exe <Not Verified; ; DDC>
2007-09-08 22:15:39 75284 --a------ E:\WINDOWS\system32\igceuijs.exe <Not Verified; ; DDC>
2007-09-08 16:15:18 76412 --a------ E:\WINDOWS\system32\bxkpyava.dll
2007-09-07 22:14:09 75284 --a------ E:\WINDOWS\system32\vrtnddhf.exe <Not Verified; ; DDC>
2007-09-06 22:19:45 120852 --a------ E:\WINDOWS\system32\roduhyff.dll
2007-09-06 22:16:43 75284 --a------ E:\WINDOWS\system32\gcdbured.exe <Not Verified; ; DDC>
2007-09-06 22:13:55 552400 ---hs---- E:\WINDOWS\system32\hgjlm.bak2
2007-09-05 22:15:36 75284 --a------ E:\WINDOWS\system32\paixxldh.exe <Not Verified; ; DDC>
2007-09-04 22:14:07 0 --a------ E:\WINDOWS\system32\SBRC.dat
2007-09-04 22:14:07 0 --a------ E:\WINDOWS\system32\SBFC.dat
2007-09-04 22:13:43 548190 ---hs---- E:\WINDOWS\system32\hgjlm.bak1
2007-09-04 22:13:35 263220 ---hs---- E:\WINDOWS\system32\mljgh.dll
2007-09-04 19:44:44 75284 --a------ E:\WINDOWS\system32\dqlfnbay.exe <Not Verified; ; DDC>
-- Find3M Report ---------------------------------------------------------------
2007-10-03 21:32:54 0 d-------- E:\Programfiler\MSN Messenger
2007-10-03 08:08:02 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\BitTorrent
2007-09-30 00:17:38 43520 --a------ E:\WINDOWS\system32\CmdLineExt03.dll
2007-09-28 13:18:58 399248 --a------ E:\WINDOWS\system32\perfh014.dat
2007-09-28 13:18:58 68228 --a------ E:\WINDOWS\system32\perfc014.dat
2007-09-24 02:30:06 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\uqm
2007-09-20 19:44:31 0 d-------- E:\Programfiler\Fellesfiler
2007-09-11 18:37:58 0 d--h----- E:\Programfiler\InstallShield Installation Information
2007-09-04 21:33:28 675139 ---hs---- E:\WINDOWS\system32\tttss.ini2
2007-09-04 19:46:22 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\Sunbelt Software
2007-09-04 19:42:55 680567 ---hs---- E:\WINDOWS\system32\tttss.bak2
2007-09-03 19:22:10 75284 --a------ E:\WINDOWS\system32\mjuthuqd.exe <Not Verified; ; DDC>
2007-09-02 16:16:07 75284 --a------ E:\WINDOWS\system32\cxwvcsae.exe <Not Verified; ; DDC>
2007-09-02 16:13:55 688006 ---hs---- E:\WINDOWS\system32\tttss.bak1
2007-09-01 16:21:59 120852 --a------ E:\WINDOWS\system32\jtsknajp.dll
2007-09-01 16:15:56 76412 --a------ E:\WINDOWS\system32\yyyenujt.dll
2007-09-01 16:15:54 75284 --a------ E:\WINDOWS\system32\kqobxyhm.exe <Not Verified; ; DDC>
2007-08-31 19:28:33 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\dvdcss
2007-08-31 16:15:54 75284 --a------ E:\WINDOWS\system32\evcbbhfc.exe <Not Verified; ; DDC>
2007-08-31 15:42:51 46 --a------ E:\WINDOWS\popcinfo.dat
2007-08-30 16:15:54 75284 --a------ E:\WINDOWS\system32\rncmsaun.exe <Not Verified; ; DDC>
2007-08-29 16:15:54 75284 --a------ E:\WINDOWS\system32\csyeqcid.exe <Not Verified; ; DDC>
2007-08-28 16:13:30 75284 --a------ E:\WINDOWS\system32\xjkptnlj.exe <Not Verified; ; DDC>
2007-08-28 16:06:25 75284 --a------ E:\WINDOWS\system32\vijpidqq.exe <Not Verified; ; DDC>
2007-08-28 00:41:59 125460 --a------ E:\WINDOWS\system32\qkcrgpej.dll
2007-08-28 00:39:33 0 d-------- E:\Documents and Settings\Per_Killer\Programdata\Skype
2007-08-27 03:37:38 125460 --a------ E:\WINDOWS\system32\ofhbyjml.dll
2007-08-26 20:22:18 125460 --a------ E:\WINDOWS\system32\okfktosj.dll
2007-08-25 16:11:19 125460 --a------ E:\WINDOWS\system32\fntoentc.dll
2007-08-25 16:08:19 76412 --a------ E:\WINDOWS\system32\qdtthdtn.dll
2007-08-25 16:02:25 124436 --a------ E:\WINDOWS\system32\mmvsfhwu.dll
2007-08-25 07:18:43 125460 --a------ E:\WINDOWS\system32\cjqxlgwl.dll
2007-08-23 22:04:02 76412 --a------ E:\WINDOWS\system32\awjwvrya.dll
2007-08-23 18:46:00 125460 --a------ E:\WINDOWS\system32\sfrhrjtq.dll
2007-08-19 18:46:01 121364 --a------ E:\WINDOWS\system32\nnovnfgg.dll
2007-08-19 15:14:26 118784 --a------ E:\WINDOWS\system32\SeismoSaver.scr <Not Verified; NuGardt Software; SeismoSaver 2>
2007-08-16 22:07:23 125460 --a------ E:\WINDOWS\system32\mdvxqeww.dll
2007-08-16 22:04:23 76412 --a------ E:\WINDOWS\system32\abytaqwy.dll
2007-08-16 22:01:31 75284 --a------ E:\WINDOWS\system32\ltdlsypp.exe <Not Verified; ; DDC>
2007-08-15 23:48:42 125460 --a------ E:\WINDOWS\system32\fegrlpdi.dll
2007-08-15 23:48:13 75284 --a------ E:\WINDOWS\system32\mupklktv.exe <Not Verified; ; DDC>
2007-08-14 23:45:59 75284 --a------ E:\WINDOWS\system32\vfwpshhd.exe <Not Verified; ; DDC>
2007-08-14 19:45:16 75284 --a------ E:\WINDOWS\system32\dpjxyycr.exe <Not Verified; ; DDC>
2007-08-14 15:40:11 125460 --a------ E:\WINDOWS\system32\xmdiclew.dll
2007-08-14 15:37:14 75284 --a------ E:\WINDOWS\system32\cucegmbx.exe <Not Verified; ; DDC>
2007-08-14 01:50:36 125460 --a------ E:\WINDOWS\system32\pentanuc.dll
2007-08-14 01:47:35 75284 --a------ E:\WINDOWS\system32\ptonhjbe.exe <Not Verified; ; DDC>
2007-08-13 02:15:17 125460 --a------ E:\WINDOWS\system32\kxdqmmfw.dll
2007-08-13 02:12:51 75284 --a------ E:\WINDOWS\system32\kkgypduj.exe <Not Verified; ; DDC>
2007-08-12 22:25:24 76412 --a------ E:\WINDOWS\system32\myxvctpw.dll
2007-08-12 07:40:32 75284 --a------ E:\WINDOWS\system32\tytdcaxy.exe <Not Verified; ; DDC>
2007-08-12 00:25:41 125460 --a------ E:\WINDOWS\system32\rjwmrsxw.dll
2007-08-12 00:25:40 75284 --a------ E:\WINDOWS\system32\rtitualw.exe <Not Verified; ; DDC>
2007-08-11 00:28:43 120852 --a------ E:\WINDOWS\system32\gnwngprs.dll
2007-08-11 00:25:41 75284 --a------ E:\WINDOWS\system32\wkyprsqk.exe <Not Verified; ; DDC>
2007-08-10 19:06:31 35546 --a------ E:\WINDOWS\DIIUnin.dat
2007-08-10 18:52:17 21840 --a------ E:\WINDOWS\system32\SIntfNT.dll
2007-08-10 18:52:17 17212 --a------ E:\WINDOWS\system32\SIntf32.dll
2007-08-10 18:52:17 12067 --a------ E:\WINDOWS\system32\SIntf16.dll
2007-08-10 18:43:06 2829 --a------ E:\WINDOWS\DIIUnin.pif
2007-08-10 18:43:06 94208 --a------ E:\WINDOWS\DIIUnin.exe <Not Verified; Blizzard Entertainment; Diablo II Uninstaller>
2007-08-10 00:23:35 75284 --a------ E:\WINDOWS\system32\hhqpckqj.exe <Not Verified; ; DDC>
2007-08-07 08:51:39 66068 --a------ E:\WINDOWS\system32\qwbtpbal.exe
2007-08-07 08:48:58 66068 --a------ E:\WINDOWS\system32\mlndeiei.exe
2007-08-07 01:21:13 66068 --a------ E:\WINDOWS\system32\sbyrixpf.exe
2007-08-06 01:21:15 120852 --a------ E:\WINDOWS\system32\dabolmqx.dll
2007-08-06 01:21:13 66068 --a------ E:\WINDOWS\system32\grrurwrs.exe
2007-08-05 22:24:14 76412 --a------ E:\WINDOWS\system32\eunhfktc.dll
2007-08-05 01:21:13 66068 --a------ E:\WINDOWS\system32\lvkdphdh.exe
2007-08-04 01:18:19 66068 --a------ E:\WINDOWS\system32\tvgmbxkg.exe
2007-08-04 01:15:35 66068 --a------ E:\WINDOWS\system32\mqkpktgd.exe
2007-08-03 01:15:35 125460 --a------ E:\WINDOWS\system32\eiqlildg.dll
2007-08-03 01:13:02 66068 --a------ E:\WINDOWS\system32\kxtatacj.exe
2007-08-03 00:49:53 66068 --a------ E:\WINDOWS\system32\gplwegek.exe
2007-08-01 22:18:14 66068 --a------ E:\WINDOWS\system32\bjsjnxqe.exe
2007-07-31 22:18:14 66068 --a------ E:\WINDOWS\system32\ktrodfkv.exe
2007-07-30 22:18:14 66068 --a------ E:\WINDOWS\system32\psucbaht.exe
2007-07-29 22:26:02 69140 --a------ E:\WINDOWS\system32\trxxmaxe.dll
2007-07-29 22:23:02 76412 --a------ E:\WINDOWS\system32\ykipwxms.dll
2007-07-29 22:20:02 66068 --a------ E:\WINDOWS\system32\hrnaftqh.exe
2007-07-29 22:17:29 66068 --a------ E:\WINDOWS\system32\cphtrkkx.exe
2007-07-25 03:08:33 66580 --a------ E:\WINDOWS\system32\kdahqcqp.dll
2007-07-25 03:02:45 66068 --a------ E:\WINDOWS\system32\mpypqhyw.exe
2007-07-24 17:20:35 66580 --a------ E:\WINDOWS\system32\opyecmah.dll
2007-07-24 17:20:29 66068 --a------ E:\WINDOWS\system32\lxxeahxx.exe
2007-07-24 17:20:29 125972 --a------ E:\WINDOWS\system32\cewcmdue.dll
2007-07-23 17:26:28 66580 --a------ E:\WINDOWS\system32\pwomddhf.dll
2007-07-23 17:20:28 66068 --a------ E:\WINDOWS\system32\mlmkdanc.exe
2007-07-22 17:27:09 66580 --a------ E:\WINDOWS\system32\eyfjvfyx.dll
2007-07-22 17:21:09 66068 --a------ E:\WINDOWS\system32\veoqhfns.exe
2007-07-21 04:27:10 66580 --a------ E:\WINDOWS\system32\xdwoqtrl.dll
2007-07-21 04:24:12 125460 --a------ E:\WINDOWS\system32\rhxlmbef.dll
2007-07-21 04:24:09 66068 --a------ E:\WINDOWS\system32\hlpyncvb.exe
2007-07-20 18:36:09 76412 --a------ E:\WINDOWS\system32\tgujjenv.dll
2007-07-20 04:27:09 66580 --a------ E:\WINDOWS\system32\ldvlldnr.dll
2007-07-20 04:24:09 66068 --a------ E:\WINDOWS\system32\pbxamtgv.exe
2007-07-19 04:24:13 66580 --a------ E:\WINDOWS\system32\fgitjwaw.dll
2007-07-19 04:24:12 66068 --a------ E:\WINDOWS\system32\cgfbwpkr.exe
2007-07-18 04:24:14 66580 --a------ E:\WINDOWS\system32\vfscxrea.dll
2007-07-18 04:21:16 66068 --a------ E:\WINDOWS\system32\ekvwtqvy.exe
2007-07-17 17:05:05 66580 --a------ E:\WINDOWS\system32\xqwjmgsj.dll
2007-07-17 17:05:01 124436 --a------ E:\WINDOWS\system32\iqwcvnjv.dll
2007-07-17 17:05:00 66068 --a------ E:\WINDOWS\system32\aoytdhdf.exe
2007-07-17 17:02:00 66068 --a------ E:\WINDOWS\system32\fhypxkha.exe
2007-07-17 06:14:27 66580 --a------ E:\WINDOWS\system32\tdjpsjda.dll
2007-07-17 06:14:26 66068 --a------ E:\WINDOWS\system32\fdmgkpnq.exe
2007-07-16 06:14:31 66580 --a------ E:\WINDOWS\system32\wimuwtfh.dll
2007-07-16 06:14:27 124436 --a------ E:\WINDOWS\system32\qtmjtjvx.dll
2007-07-16 06:11:42 66068 --a------ E:\WINDOWS\system32\ohjvwunl.exe
2007-07-16 02:34:42 124436 --a------ E:\WINDOWS\system32\xywprssm.dll
2007-07-16 02:31:41 66580 --a------ E:\WINDOWS\system32\rkeefaot.dll
2007-07-16 02:29:59 66068 --a------ E:\WINDOWS\system32\eqxdvwbi.exe
2007-07-15 14:45:45 66580 --a------ E:\WINDOWS\system32\edlnwxgr.dll
2007-07-15 14:42:46 124436 --a------ E:\WINDOWS\system32\rdcllipk.dll
2007-07-15 14:39:44 66068 --a------ E:\WINDOWS\system32\oobdhlig.exe
2007-07-14 15:47:08 737280 --a------ E:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2007-07-14 15:32:28 528 -r-hs---- E:\WINDOWS\egirllic151
2007-07-14 14:39:47 66580 --a------ E:\WINDOWS\system32\snhcduqj.dll
2007-07-14 14:39:45 66068 --a------ E:\WINDOWS\system32\dqwhtill.exe
2007-07-13 18:36:44 76412 --a------ E:\WINDOWS\system32\hyydlxao.dll
2007-07-13 14:42:44 66580 --a------ E:\WINDOWS\system32\rcnuxdhn.dll
2007-07-13 14:39:44 66068 --a------ E:\WINDOWS\system32\lmvfamku.exe
2007-07-12 14:38:44 66580 --a------ E:\WINDOWS\system32\uvrmjwvj.dll
2007-07-12 14:38:40 66068 --a------ E:\WINDOWS\system32\djqiwoev.exe
2007-07-08 18:32:27 50708 --a------ E:\WINDOWS\system32\elwkgeon.exe <Not Verified; ; DDC>
2007-07-07 18:32:28 50708 --a------ E:\WINDOWS\system32\qeqccmvv.exe <Not Verified; ; DDC>
2007-07-06 18:36:05 76412 --a------ E:\WINDOWS\system32\kryjajhg.dll
2007-07-06 18:30:18 50708 --a------ E:\WINDOWS\system32\rqplvuua.exe <Not Verified; ; DDC>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02633FD6-4FBE-47B1-8966-7C223969A25B}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{709AFF26-6BB0-4AD3-A3A3-1286592465D6}]
05/26/2007 04:00 AM 29206 --a------ E:\WINDOWS\system32\nnnomml.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9B5CFE0B-BE3B-4552-811D-84539C0DCFA5}]
09/04/2007 10:13 PM 263220 ---hs---- E:\WINDOWS\system32\mljgh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1}]
07/29/2007 10:26 PM 69140 --a------ E:\WINDOWS\system32\trxxmaxe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E980DD43-BEDE-46DD-BC03-BB7B85544898}]
10/02/2007 12:57 AM 121364 --a------ E:\WINDOWS\system32\ukwhuvtf.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="H:\Prog\Java\bin\jusched.exe" [07/12/2007 04:00 AM]
"LVCOMSX"="E:\WINDOWS\system32\LVCOMSX.EXE" [10/08/2004 11:52 AM]
"NvCplDaemon"="E:\WINDOWS\system32\NvCpl.dll" [08/11/2006 09:43 PM]
"nwiz"="nwiz.exe" [08/11/2006 09:43 PM E:\WINDOWS\system32\nwiz.exe]
"Smapp"="E:\Programfiler\Analog Devices\SoundMAX\SMTray.exe" [05/05/2003 08:57 AM]
"QuickTime Task"="E:\Programfiler\QuickTime\qttask.exe" [04/30/2006 01:05 PM]
"PKR Pal"="H:\Sindre\Spill\PKR\pkrpal.exe" [09/19/2007 12:18 AM]
"PWRISOVM.EXE"="H:\Prog\PowerISO\PWRISOVM.EXE" [08/07/2007 02:05 AM]
"SearchIndexer"="E:\WINDOWS\system32\ymqwfikn.dll" [10/03/2007 09:33 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="E:\Programfiler\MSN Messenger\MsnMsgr.exe" [01/19/2007 01:54 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"*CmaudioMon"=rundll32.exe bot007dll.dll,_EntryPoint@16
E:\Documents and Settings\Per_Killer\Start-meny\Programmer\Oppstart\
Adobe Gamma.lnk - E:\Programfiler\Fellesfiler\Adobe\Calibration\Adobe Gamma Loader.exe [12:00:00 AM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{709AFF26-6BB0-4AD3-A3A3-1286592465D6}"= E:\WINDOWS\system32\nnnomml.dll [05/26/2007 04:00 AM 29206]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljgh]
E:\WINDOWS\system32\mljgh.dll 09/04/2007 10:13 PM 263220 E:\WINDOWS\system32\mljgh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnomml]
nnnomml.dll 05/26/2007 04:00 AM 29206 E:\WINDOWS\system32\nnnomml.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssttt]
E:\WINDOWS\system32\ssttt.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CookiePatrol]
C:\Prog\PestPatrol\CookiePatrol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"C:\Prog\D-Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
C:\Prog\Internet Download Manager\IDMan.exe /onboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Prog\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Prog\Logitech\Video\ManifestEngine.exe boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Prog\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Prog\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"E:\Programfiler\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PestPatrol Control Center]
C:\Prog\PestPatrol\PPControl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPMemCheck]
C:\Prog\PestPatrol\PPMemCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"E:\Programfiler\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
E:\Programfiler\VIA\RAID\raid_tool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
E:\Sindre\Spill\Steam\\Steam.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Macromedia Licensing Service"=3 (0x3)
"iPodService"=3 (0x3)
"IDriverT"=3 (0x3)
"Bonjour Service"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\SETUP.EXE
-- End of Deckard's System Scanner: finished at 2007-10-04 02:33:18 ------------