Logfile of random's system information tool 1.06 (written by random/random)
Run by USER at 2010-01-06 23:37:01
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 34 GB (60%) free of 57 GB
Total RAM: 958 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:37:42 PM, on 1/6/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\S3trayp.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\USER\Desktop\avprep\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\USER.exe
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [yifojoluz] Rundll32.exe "c:\windows\system32\pawajinu.dll",a
O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [Kwatehisuketomiv] rundll32.exe "C:\WINDOWS\orixozoquq.dll",Startup
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [iPhone PC Suite] C:\Program Files\NetDragon\91 Mobile\iPhone\iPhone PC Suite.exe /start
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US
ee://aol/imAppO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Windows Defender.lnk = C:\plugins\Server.jar
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save YouTube Video -
res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP4.htm
O8 - Extra context menu item: Save YouTube Video as MP3 -
res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: yuyaruzot - {c5aca147-9777-4d9e-8e84-98cee0d204c0} - (no file)
O21 - SSODL: yuviyokum - {f621787c-a3c7-4767-94b4-549082b98601} - c:\windows\system32\buvoyaki.dll (file missing)
O21 - SSODL: wiwebugow - {870f52c7-777c-48e1-b805-19d5c542f039} - c:\windows\system32\wotuzapi.dll (file missing)
O21 - SSODL: hemodokor - {b5973627-f664-4bdf-9636-5410786c46fd} - c:\windows\system32\yuhodose.dll (file missing)
O21 - SSODL: timumuwok - {8b709785-59ae-4b96-863b-1949a8823acb} - c:\windows\system32\pawajinu.dll
O22 - SharedTaskScheduler: kupuhivus - {f621787c-a3c7-4767-94b4-549082b98601} - c:\windows\system32\buvoyaki.dll (file missing)
O22 - SharedTaskScheduler: gahurihor - {870f52c7-777c-48e1-b805-19d5c542f039} - c:\windows\system32\wotuzapi.dll (file missing)
O22 - SharedTaskScheduler: mujuzedij - {b5973627-f664-4bdf-9636-5410786c46fd} - c:\windows\system32\yuhodose.dll (file missing)
O22 - SharedTaskScheduler: gahurihor - {8b709785-59ae-4b96-863b-1949a8823acb} - c:\windows\system32\pawajinu.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 8159 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-12-11 1111320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-11-25 1230080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-04 41368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-09-04 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-11-25 1230080]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2008-05-16 94208]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-10-16 16855552]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-12-11 2043160]
"HP Software Update"=c:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2004-09-13 49152]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-07-13 292128]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-09-04 148888]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2008-05-20 204800]
"yifojoluz"=c:\windows\system32\pawajinu.dll [65535-65535-31889 94208]
"winupdate86.exe"=C:\WINDOWS\system32\winupdate86.exe []
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2009-09-25 185640]
"Kwatehisuketomiv"=C:\WINDOWS\orixozoquq.dll,Startup []
"CarboniteSetupLite"=C:\Program Files\Carbonite\CarbonitePreinstaller.exe [2009-08-04 318096]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-08-09 1961984]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-04 1667584]
"iPhone PC Suite"=C:\Program Files\NetDragon\91 Mobile\iPhone\iPhone PC Suite.exe /start []
"HijackThis startup scan"=C:\Program Files\Trend Micro\HijackThis\HijackThis.exe [2009-12-28 396288]
"Aim6"=C:\Program Files\AIM6\aim6.exe [2009-07-09 49968]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
Windows Defender.lnk - C:\plugins\Server.jar
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\kbdsock.dll,hikorajo.dll c:\windows\system32\pawajinu.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-08-28 11952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
yuyaruzot - {c5aca147-9777-4d9e-8e84-98cee0d204c0}
yuviyokum - {f621787c-a3c7-4767-94b4-549082b98601} - c:\windows\system32\buvoyaki.dll []
wiwebugow - {870f52c7-777c-48e1-b805-19d5c542f039} - c:\windows\system32\wotuzapi.dll []
hemodokor - {b5973627-f664-4bdf-9636-5410786c46fd} - c:\windows\system32\yuhodose.dll []
timumuwok - {8b709785-59ae-4b96-863b-1949a8823acb} - c:\windows\system32\pawajinu.dll [65535-65535-31889 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
kupuhivus - {f621787c-a3c7-4767-94b4-549082b98601} - c:\windows\system32\buvoyaki.dll []
gahurihor - {870f52c7-777c-48e1-b805-19d5c542f039} - c:\windows\system32\wotuzapi.dll []
mujuzedij - {b5973627-f664-4bdf-9636-5410786c46fd} - c:\windows\system32\yuhodose.dll []
gahurihor - {8b709785-59ae-4b96-863b-1949a8823acb} - c:\windows\system32\pawajinu.dll [65535-65535-31889 94208]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
humoyofa.dll
falefula.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Documents and Settings\USER\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe"="C:\Documents and Settings\USER\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\iPhoneBrowser\iPhoneBrowser.exe"="C:\Program Files\iPhoneBrowser\iPhoneBrowser.exe:*:Enabled:iPhoneBrowser"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4581e1e8-89be-11de-817e-00e04d8bcd38}]
shell\AutoRun\command - F:\.\Vado\Vado.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa33dfbf-8904-11de-82ff-00e04d8bcd38}]
shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa33dfdb-8904-11de-82ff-00e04d8bcd38}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe
shell\Explore\command - autorun.exe
shell\Open\command - autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e5ed345c-8946-11de-817d-00e04d8bcd38}]
shell\AutoRun\command - F:\RUNDLL32.EXE
======List of files/folders created in the last 1 months======
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\wimatiku.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\wazuloro.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\vuyivose.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\vipafiyu.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\vijogojo.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\vidinesa.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\tugaroni.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\soyabodu.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\samorasa.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\pawajinu.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\papamesu.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\midogiru.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\luruvube.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\kodesalo.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\kiviyehi.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\kijafigo.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\jojubasa.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\hikorajo.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\fidetiga.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\falefula.dll
65535-65535-31889 411:31889:475 ----ASH---- C:\WINDOWS\system32\dosakoha.dll
2010-01-06 23:37:01 ----D---- C:\rsit
2010-01-06 23:30:32 ----D---- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2010-01-06 23:30:04 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2010-01-06 22:35:39 ----D---- C:\Program Files\HW Monitor
2010-01-06 22:21:25 ----D---- C:\Program Files\BIOS Update
2010-01-06 21:08:32 ----A---- C:\WINDOWS\2512406.exe
2010-01-06 11:27:55 ----SH---- C:\WINDOWS\system32\niwogepi.dll
2010-01-05 10:34:43 ----SH---- C:\WINDOWS\system32\habebesi.dll
2010-01-04 18:31:35 ----D---- C:\Documents and Settings\USER\Application Data\vlc
2010-01-04 18:29:47 ----D---- C:\Program Files\VideoLAN
2010-01-03 22:15:56 ----A---- C:\WINDOWS\system32\PR19.DLL
2010-01-03 13:18:10 ----D---- C:\Program Files\TrendMicro
2009-12-31 06:16:59 ----D---- C:\Program Files\ExplorerXP
2009-12-31 06:16:21 ----D---- C:\!KillBox
2009-12-31 06:13:32 ----D---- C:\Program Files\a-squared Free
2009-12-30 15:55:10 ----A---- C:\WINDOWS\system32\flags.ini
2009-12-30 14:06:27 ----A---- C:\cleanup.exe
2009-12-30 14:06:27 ----A---- C:\cleanup.bat
2009-12-29 15:41:23 ----D---- C:\WINDOWS\pss
2009-12-29 15:14:08 ----A---- C:\WINDOWS\system32\svchost.exe.exp.log
2009-12-28 21:39:17 ----D---- C:\Program Files\Trend Micro
2009-12-28 17:05:03 ----A---- C:\WINDOWS\ntbtlog.txt
2009-12-28 16:50:16 ----D---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-12-28 16:37:15 ----SHD---- C:\Documents and Settings\USER\Application Data\SystemProc
2009-12-26 12:22:42 ----RSHD---- C:\plugins
2009-12-26 11:46:11 ----D---- C:\Program Files\Common Files\NetDragon
2009-12-26 11:43:23 ----D---- C:\Program Files\NetDragon
2009-12-26 11:13:03 ----D---- C:\Program Files\DigiDNA
2009-12-22 20:01:29 ----D---- C:\Program Files\iPhoneBrowser
2009-12-22 19:49:24 ----D---- C:\Documents and Settings\USER\Application Data\DiskAid
2009-12-18 12:05:00 ----D---- C:\Program Files\JDownloader
2009-12-18 10:48:53 ----D---- C:\Program Files\Seagate
2009-12-18 10:48:53 ----D---- C:\Documents and Settings\All Users\Application Data\Seagate
2009-12-18 10:46:25 ----D---- C:\Program Files\Carbonite
2009-12-18 10:46:24 ----SHD---- C:\WINDOWS\ftpcache
2009-12-16 20:50:43 ----D---- C:\Program Files\AviSynth 2.5
2009-12-16 20:50:22 ----D---- C:\Program Files\Red Kawa
2009-12-15 14:33:01 ----D---- C:\WINDOWS\system32\NtmsData
2009-12-15 03:02:31 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-12-15 03:01:20 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2009-12-15 02:07:52 ----D---- C:\Program Files\WBFS
2009-12-14 03:09:54 ----D---- C:\WINDOWS\system32\XPSViewer
2009-12-14 03:09:42 ----D---- C:\Program Files\MSBuild
2009-12-14 03:09:37 ----D---- C:\WINDOWS\system32\en-US
2009-12-14 03:09:19 ----D---- C:\Program Files\Reference Assemblies
2009-12-14 03:08:26 ----A---- C:\WINDOWS\system32\prntvpt.dll
2009-12-14 03:08:25 ----A---- C:\WINDOWS\system32\xpssvcs.dll
2009-12-14 03:08:25 ----A---- C:\WINDOWS\system32\xpsshhdr.dll
2009-12-14 03:08:24 ----D---- C:\fe4c64ab2e063b63773958deafcd0c
2009-12-14 03:02:09 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2009-12-14 03:02:01 ----D---- C:\Program Files\MSXML 6.0
2009-12-13 19:23:18 ----A---- C:\WINDOWS\system32\TubeFinder.exe
2009-12-13 19:23:15 ----A---- C:\WINDOWS\system32\VB6STKIT.DLL
2009-12-13 19:23:15 ----A---- C:\WINDOWS\system32\VB6FR.DLL
2009-12-13 19:23:15 ----A---- C:\WINDOWS\system32\PCCLPFR.DLL
2009-12-13 19:23:14 ----A---- C:\WINDOWS\system32\MSCMCFR.DLL
2009-12-13 19:23:13 ----D---- C:\Documents and Settings\USER\Application Data\FreeFLVConverter
2009-12-13 19:23:13 ----A---- C:\WINDOWS\system32\CMDLGFR.DLL
2009-12-11 18:36:16 ----A---- C:\WINDOWS\system32\ptpusb.dll
2009-12-11 18:36:08 ----A---- C:\WINDOWS\system32\ptpusd.dll
2009-12-10 03:02:22 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2009-12-10 03:02:04 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2009-12-10 03:01:31 ----HDC---- C:\WINDOWS\$NtUninstallKB976325$
2009-12-10 03:01:08 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2009-12-10 03:00:58 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2009-12-10 03:00:44 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
======List of files/folders modified in the last 1 months======
2010-01-06 23:36:46 ----D---- C:\WINDOWS\Prefetch
2010-01-06 23:30:34 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-06 23:02:30 ----D---- C:\Program Files\Mozilla Firefox
2010-01-06 22:36:28 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-06 22:35:39 ----RD---- C:\Program Files
2010-01-06 22:35:38 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-06 22:27:19 ----D---- C:\WINDOWS
2010-01-06 22:27:14 ----RSH---- C:\boot.ini
2010-01-06 22:21:58 ----D---- C:\WINDOWS\system32\drivers
2010-01-06 21:40:52 ----D---- C:\WINDOWS\Temp
2010-01-06 21:14:49 ----D---- C:\WINDOWS\system32
2010-01-06 21:14:21 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2010-01-06 21:12:36 ----A---- C:\WINDOWS\win.ini
2010-01-06 21:12:36 ----A---- C:\WINDOWS\system.ini
2010-01-06 15:04:48 ----D---- C:\Program Files\Common Files
2010-01-06 15:04:30 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-06 13:43:38 ----HD---- C:\$AVG8.VAULT$
2010-01-05 17:51:21 ----A---- C:\WINDOWS\NeroDigital.ini
2010-01-04 13:08:19 ----D---- C:\WINDOWS\system32\Restore
2010-01-03 13:18:12 ----SHD---- C:\WINDOWS\Installer
2010-01-03 13:18:12 ----HD---- C:\Config.Msi
2010-01-03 09:49:30 ----SD---- C:\WINDOWS\Tasks
2010-01-03 06:49:10 ----SHD---- C:\RECYCLER
2010-01-01 00:13:23 ----D---- C:\Program Files\Internet Explorer
2009-12-31 19:51:03 ----SHD---- C:\System Volume Information
2009-12-31 17:26:19 ----D---- C:\WINDOWS\security
2009-12-30 15:34:56 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-12-29 23:57:46 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2009-12-29 14:41:23 ----A---- C:\WINDOWS\ODBC.INI
2009-12-29 01:24:27 ----D---- C:\WINDOWS\PeerNet
2009-12-28 19:00:13 ----D---- C:\WINDOWS\Media
2009-12-28 17:05:38 ----D---- C:\Documents and Settings
2009-12-18 10:45:35 ----HD---- C:\WINDOWS\inf
2009-12-17 15:54:15 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-12-16 14:52:01 ----D---- C:\Program Files\Cheat Engine
2009-12-15 03:54:24 ----RSD---- C:\WINDOWS\assembly
2009-12-15 03:47:09 ----D---- C:\WINDOWS\Microsoft.NET
2009-12-15 03:14:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-12-15 03:12:45 ----D---- C:\WINDOWS\WinSxS
2009-12-15 03:05:05 ----A---- C:\WINDOWS\imsins.BAK
2009-12-15 03:04:51 ----D---- C:\WINDOWS\system32\CatRoot
2009-12-15 03:02:28 ----HD---- C:\WINDOWS\$hf_mig$
2009-12-14 03:09:33 ----RSD---- C:\WINDOWS\Fonts
2009-12-14 03:08:53 ----D---- C:\WINDOWS\system32\spool
2009-12-13 19:21:01 ----D---- C:\Program Files\Common Files\DVDVideoSoft
2009-12-12 19:07:00 ----D---- C:\Documents and Settings\USER\Application Data\Apple Computer
2009-12-11 18:36:40 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
2009-12-10 17:21:12 ----D---- C:\WINDOWS\Minidump
2009-12-08 21:40:06 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-08-28 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-08-28 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-08-14 108552]
R1 BIOS;BIOS; \??\C:\WINDOWS\system32\drivers\BIOS.sys []
R1 BS_I2cIo;BS_I2cIo; \??\C:\WINDOWS\system32\drivers\BS_I2cIo.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 BS_Flash;BS_Flash; \??\C:\Program Files\BIOS Update\Award\BS_Flash.sys []
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-10-27 138240]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-12-14 51120]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-12-14 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-12-14 21744]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-10-16 4615168]
R3 ltmodem5;Lucent Modem Driver; C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys [2003-03-31 625537]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2008-08-28 529920]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\F:\everestultimate500\kerneld.wnt []
S3 ndisdrv;ndisdrv; \??\C:\WINDOWS\system32\ndisdrv.sys []
S3 RimUsb;BlackBerry Smartphone; C:\WINDOWS\System32\Drivers\RimUsb.sys [2008-04-16 22784]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-07-09 39424]
S3 winsts;winsts; \??\C:\WINDOWS\system32\winsts.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-07-09 144712]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-08-28 297752]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-25 189736]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-09-04 152984]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-07-13 542496]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------