Sorry to take so long. Was running the scan for ark.txt file last night and the computer crashed. Then it hung when trying to reboot. Ran the scan today, saved it, and when I went to the internet, the computer crashed again. Thunderbird Email program was working fine though. Now I'm able to get on, but only because when I clicked MicrosSoft Error reporting, Chrome opened okay, but without the tabs I had open. So, at any rate. Here's the files requested. Thank you again for your time and effort. When I get paid again in mid-September, I will definitely donate.
DDS (Ver_10-03-17.01) - NTFSx86
Run by Dantian at 3:45:12.54 on Tue 08/24/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.217 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
C:\Program Files\IDrive\IDriveE Service.exe
C:\Program Files\IDrive\IDriveWebM.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\IDrive\IDriveETray.exe
C:\Program Files\IDrive\IDriveEBackground.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Dantian\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Documents and Settings\Dantian\Desktop\MALWARE HELP\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.netflix.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mWinlogon: Shell=explorer.exe
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: WsftpBrowserHelper Class: {601ed020-fb6c-11d3-87d8-0050da59922b} - c:\program files\ws_ftp pro\wsbho2k0.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [IDriveE Startup] "c:\program files\idrive\IDrvieEStartup.exe" Hide
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Google Update] "c:\documents and settings\dantian\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [CreateCD_Reminder] c:\windows\sonysys\vaio recovery\reminder.exe
mRun: [VAIO Recovery] c:\windows\sonysys\vaio recovery\PartSeal.exe
mRun: [SonyPowerCfg] c:\program files\sony\vaio power management\SPMgr.exe
mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
StartupFolder: c:\docume~1\dantian\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\dantian\startm~1\programs\startup\idrive~1.lnk - c:\program files\idrive\IDriveEReg2ini.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~2.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\device~2.lnk - c:\program files\olympus\devicedetector\DevDtct2.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\direct~1.lnk - c:\program files\olympus\devicedetector\DirectrecConfig.exe
IE: &AOL Toolbar search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: aol.com\free
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.pogo.com/game/deluxe/zuma/popcaploader_v6.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FA945BB6-9D37-43FC-9B2A-AF09F56CBBF0} - hxxp://www.musicmatch.com/form/support/tech/diagnostics/cabs/DiagCollectionControl.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
Notify: VESWinlogon - VESWinlogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\progra~1\qualcomm\eudora\EuShlExt.dll
Hosts: 127.0.0.1
www.spywareinfo.comHosts: 17.250.248.77 idisk0.mac.com idisk1.mac.com idisk2.mac.com idisk3.mac.com idisk4.mac.com idisk5.mac.com idisk6.mac.com idisk7.mac.com idisk8.mac.com idisk9.mac.com idisk10.mac.com idisk11.mac.com idisk12.mac.com idisk13.mac.com idisk14.mac.com idisk15.mac.com idisk16.mac.com idisk17.mac.com idisk18.mac.com idisk19.mac.com idisk20.mac.com idisk21.mac.com idisk22.mac.com idisk23.mac.com idisk24.mac.com idisk25.mac.com
Hosts: 10.120.122.8 HP000D9D1A7D97
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\dantian\applic~1\mozilla\firefox\profiles\uejmhuiw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/calendar/render?utm_campaign=en&utm_source=en-ha-na-us-sk&utm_medium=ha&utm_term=online+calendar&gsessionid=hEEX1tvQISJXqmY86-CIJw
FF - prefs.js: keyword.URL - chrome://google-partner/locale/partner.properties
FF - component: c:\documents and settings\dantian\application data\mozilla\firefox\profiles\uejmhuiw.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\dantian\application data\mozilla\firefox\profiles\uejmhuiw.default\extensions\
moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\dantian\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-24 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-2-13 29584]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-24 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-15 308136]
R2 IDriveE Service;IDriveE Service;c:\program files\idrive\IDriveE Service.exe [2008-12-27 131072]
R2 IDrivePlugin;IDrivePlugin;c:\program files\idrive\IDriveWebM.exe [2008-12-27 58832]
S3 Npfspdi;Npfspdi;c:\windows\system32\netsh.exe [2004-11-20 86016]
S3 P1171VID;Creative WebCam Notebook #2;c:\windows\system32\drivers\P1171Vid.sys [2005-9-24 91392]
S3 VVRUSB;VVRUSB Device;c:\windows\system32\drivers\VVRUSB.sys [2005-3-11 38479]
=============== Created Last 30 ================
==================== Find3M ====================
2010-07-23 15:38:37 610 ----a-w- c:\docume~1\dantian\applic~1\wklnhst.dat
2010-07-16 23:22:43 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2010-07-16 23:22:42 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2010-07-16 23:22:37 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-07-15 15:04:53 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-15 15:04:50 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-15 15:03:26 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15:28 832512 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15:26 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:15:26 17408 ----a-w- c:\windows\system32\corpol.dll
2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2008-10-05 09:19:53 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100520081006\index.dat
2009-12-20 22:54:59 16384 --sha-w- c:\windows\temp\cookies\index.dat
2009-12-20 22:54:59 16384 --sha-w- c:\windows\temp\history\history.ie5\index.dat
2009-12-20 22:54:59 32768 --sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat
============= FINISH: 3:46:52.48 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 3/5/2005 4:06:47 PM
System Uptime: 8/23/2010 10:40:56 AM (17 hours ago)
Processor: Intel(R) Pentium(R) M processor 1.73GHz | N/A | 1729/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 88 GiB total, 35.488 GiB free.
D: is CDROM (UDF)
E: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1758: 5/26/2010 10:00:22 AM - Software Distribution Service 3.0
RP1759: 5/27/2010 12:19:00 PM - System Checkpoint
RP1760: 5/28/2010 12:26:50 PM - System Checkpoint
RP1761: 5/29/2010 12:32:23 PM - System Checkpoint
RP1762: 6/4/2010 12:01:27 AM - Avg Update
RP1763: 6/4/2010 12:40:17 AM - Software Distribution Service 3.0
RP1764: 6/5/2010 3:26:58 AM - System Checkpoint
RP1765: 6/6/2010 1:31:01 PM - System Checkpoint
RP1766: 6/7/2010 7:27:32 PM - System Checkpoint
RP1767: 6/8/2010 7:43:50 PM - System Checkpoint
RP1768: 6/10/2010 3:42:26 AM - System Checkpoint
RP1769: 6/11/2010 4:25:22 AM - System Checkpoint
RP1770: 6/11/2010 4:58:52 AM - Software Distribution Service 3.0
RP1771: 6/12/2010 12:34:06 AM - Software Distribution Service 3.0
RP1772: 6/13/2010 12:48:21 AM - System Checkpoint
RP1773: 6/14/2010 12:57:20 AM - System Checkpoint
RP1774: 6/15/2010 1:53:11 PM - System Checkpoint
RP1775: 6/18/2010 7:24:41 PM - System Checkpoint
RP1776: 6/19/2010 9:02:36 PM - System Checkpoint
RP1777: 6/20/2010 9:58:11 PM - System Checkpoint
RP1778: 6/21/2010 10:30:50 PM - System Checkpoint
RP1779: 6/23/2010 10:03:14 AM - System Checkpoint
RP1780: 6/23/2010 5:37:03 PM - Software Distribution Service 3.0
RP1781: 6/24/2010 5:59:56 PM - System Checkpoint
RP1782: 6/25/2010 9:55:51 AM - Avg Update
RP1783: 6/26/2010 1:50:00 PM - System Checkpoint
RP1784: 6/27/2010 2:20:53 PM - System Checkpoint
RP1785: 6/28/2010 8:21:12 PM - System Checkpoint
RP1786: 6/29/2010 8:26:43 PM - System Checkpoint
RP1787: 6/30/2010 9:46:30 PM - System Checkpoint
RP1788: 7/1/2010 10:07:00 PM - System Checkpoint
RP1789: 7/2/2010 11:14:55 PM - System Checkpoint
RP1790: 7/4/2010 10:46:38 AM - System Checkpoint
RP1791: 7/5/2010 5:24:57 PM - System Checkpoint
RP1792: 7/6/2010 6:10:17 PM - System Checkpoint
RP1793: 7/7/2010 6:20:37 PM - System Checkpoint
RP1794: 7/8/2010 7:42:00 PM - System Checkpoint
RP1795: 7/9/2010 8:26:14 PM - System Checkpoint
RP1796: 7/10/2010 8:38:11 PM - System Checkpoint
RP1797: 7/12/2010 9:16:32 AM - System Checkpoint
RP1798: 7/13/2010 1:16:54 PM - System Checkpoint
RP1799: 7/14/2010 10:00:50 AM - Software Distribution Service 3.0
RP1800: 7/15/2010 10:01:01 AM - Avg Update
RP1801: 7/15/2010 10:05:10 AM - Avg Update
RP1802: 7/16/2010 12:09:43 PM - System Checkpoint
RP1803: 7/16/2010 6:18:09 PM - SetPoint 4.80
RP1804: 7/17/2010 6:19:09 PM - System Checkpoint
RP1805: 7/18/2010 6:56:36 PM - System Checkpoint
RP1806: 7/19/2010 7:38:54 PM - System Checkpoint
RP1807: 7/21/2010 10:00:16 AM - Avg Update
RP1808: 7/22/2010 5:13:02 PM - System Checkpoint
RP1809: 7/23/2010 6:07:00 PM - System Checkpoint
RP1810: 7/24/2010 9:01:28 PM - System Checkpoint
RP1811: 7/26/2010 1:41:58 PM - System Checkpoint
RP1812: 7/27/2010 2:23:22 PM - System Checkpoint
RP1813: 7/28/2010 3:01:12 PM - System Checkpoint
RP1814: 7/29/2010 4:17:04 PM - System Checkpoint
RP1815: 7/30/2010 4:31:14 PM - System Checkpoint
RP1816: 7/31/2010 4:58:51 PM - System Checkpoint
RP1817: 8/1/2010 5:28:32 PM - System Checkpoint
RP1818: 8/2/2010 5:46:43 PM - System Checkpoint
RP1819: 8/3/2010 10:00:31 AM - Software Distribution Service 3.0
RP1820: 8/4/2010 10:30:57 AM - System Checkpoint
RP1821: 8/5/2010 11:12:53 AM - System Checkpoint
RP1822: 8/6/2010 11:46:37 AM - System Checkpoint
RP1823: 8/7/2010 1:48:22 PM - System Checkpoint
RP1824: 8/8/2010 3:06:43 PM - System Checkpoint
RP1825: 8/9/2010 5:43:27 PM - System Checkpoint
RP1826: 8/10/2010 8:47:00 PM - System Checkpoint
RP1827: 8/13/2010 5:33:19 AM - Software Distribution Service 3.0
RP1828: 8/14/2010 10:18:44 AM - System Checkpoint
RP1829: 8/15/2010 10:41:35 AM - System Checkpoint
RP1830: 8/16/2010 12:14:38 PM - Avg Update
RP1831: 8/17/2010 2:00:07 PM - System Checkpoint
RP1832: 8/18/2010 2:57:43 PM - System Checkpoint
RP1833: 8/19/2010 6:13:48 PM - System Checkpoint
RP1834: 8/20/2010 6:45:12 PM - System Checkpoint
RP1835: 8/22/2010 11:05:08 AM - System Checkpoint
RP1836: 8/23/2010 11:06:06 AM - System Checkpoint
RP1837: 8/23/2010 9:54:46 PM - Removed Xara Webstyle 4
RP1838: 8/23/2010 10:03:59 PM - Installed HiJackThis
==== Installed Programs ======================
3ivx D4 4.5.1 Decoder (remove only)
AceMoney
Adobe Acrobat - Reader 6.0.2 Update
Adobe Acrobat 4.0, 5.0
Adobe Acrobat 6.0.1 Professional
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe InDesign CS2
Adobe Photoshop 6.0
Adobe Photoshop CS
Adobe Reader 7.0.9
Adobe Stock Photos 1.0
Adobe SVG Viewer
Adobe® Photoshop® Album Starter Edition 3.0
Astral Interface 5 by Magnus
Audacity 1.2.6
Audio/Video Conference 4.1+
AutoLogon 1.0
AVG Free 9.0
Canon Camera Access Library
Canon DIGITAL CAMERA Solution Disk Software Guide
CANON iMAGE GATEWAY Task for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon MP Navigator EX 1.0
Canon MP470 series
Canon MP470 series User Registration
Canon My Printer
Canon Personal Printing Guide
Canon PowerShot SD1300 IS_IXUS 105 Camera User Guide
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC 8
Canon Utilities Easy-PhotoPrint EX
Canon Utilities Movie Uploader for YouTube
Canon Utilities MyCamera
Canon Utilities PhotoStitch
Canon Utilities Solution Menu
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
CleanCenter v1.35.02
Click to DVD 2.0.02 Menu Data
Click to DVD 2.2.10
CONNECT
Creative PC-CAM Center
Creative WebCam Monitor
Creative WebCam Notebook Driver (1.04.01.0322)
Creative WebCam Notebook User's Guide (English)
Critical Update for Windows Media Player 11 (KB959772)
DVgate Plus
EarMaster Pro 4
Easy-WebPrint
erLT
Eudora
Genuine Fractals
Google Chrome
Google Earth
GoToMeeting 4.0.0.320
High Definition Audio Driver Package - KB835221
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
iDisk Utility for Windows
IDrive version 3.2.2 December 26 2008
Indeo® software
Intel(R) Graphics Media Accelerator Driver for Mobile
Intel(R) PRO Network Connections Drivers
Intel(R) PROSet/Wireless Software
InterVideo WinDVD 5 for VAIO
InterVideo WinDVDX
Ipswitch WS_FTP Pro
iTunes
Java(TM) 6 Update 13
Java(TM) 6 Update 14
Java(TM) 6 Update 6
Java(TM) 6 Update 7
logiDecrypt
Macromedia Contribute
Macromedia Dreamweaver MX
Macromedia Extension Manager
Macromedia Fireworks MX
Macromedia Flash MX
Macromedia FreeHand MX
mCore
mDriver
Memory Stick Formatter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Producer for Microsoft Office PowerPoint 2003
Microsoft Silverlight
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows Media Video 9 VCM
Microsoft Works
mMHouse
MoodLogic
Mozilla Firefox (3.0.15)
Mozilla Thunderbird (2.0.0.24)
mPfMgr
mProSafe
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB925673)
mWlsSafe
mXML
Netscape Internet Service Setup
Network ScanGear Ver.2.01
NVIDIA Drivers
Olympus DSS Player
Olympus Voice Album
OpenMG Limited Patch 4.0-04-08-02-01
OpenMG Secure Module 4.0.00
OpenOffice.org 3.1
PictureGear Studio 2.0
PIXMA Extended Survey Program
QuarkXPress 6.5
QuickBooks Pro 99
QuickTime
RealPlayer
Realtek High Definition Audio Driver
RedShift 3
Samsung ML-1710 Seriess
ScanSoft OmniPage SE 4
ScanToWeb
Scratch
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB2183461)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Setting Utility Series
Skype™ 3.8
Sonic RecordNow!
SonicStage 2.1.02
SonicStage Mastering Studio Audio Filter Custom Preset
Sony Certificate PCH
Sony USB Mouse
Sony Utilities DLL
Sony Video Shared Library
Spybot - Search & Destroy
TBS WMP Plug-in
The Human 3D
The Journey to Wild Divine
The Wild Divine Grapher
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
USB MassStorage CardReader
VAIO Control Center
VAIO Entertainment Platform
VAIO Event Service
VAIO Help and Support
VAIO Launcher
VAIO Light Flo Wallpaper
VAIO Media 3.1
VAIO Media Integrated Server 3.1
VAIO Media Redistribution 3.1
VAIO Original Screen Saver
VAIO Original Screen Saver VAIO Scene SD Wide Contents
VAIO Power Management
VAIO Registration
VAIO Survey Standalone
VAIO Update 2
VAIO Wireless Utility
VAIO Zone
WebFldrs XP
Welcome to VAIO life
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows XP Service Pack 3
WinPatrol 2009
WinZip 14.0
Wireless Switch Setting Utility
Wisdom Quest
Xara Dreamweaver Extension 1.03
Xara ScreenMaker3D
Xara Xtreme
Xara Xtreme 4 e-version
XML Paper Specification Shared Components Pack 1.0
XPressMath XTensions
==== End Of File ===========================
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-08-24 14:01:52
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Dantian\LOCALS~1\Temp\pxtdapow.sys
---- Kernel code sections - GMER 1.0.15 ----
init C:\WINDOWS\system32\drivers\tifmsony.sys entry point in "init" section [0xF75D6280]
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\hjgruiwtpxjkji.sys (*** hidden *** ) [SYSTEM] hjgruiibcjxvni <-- ROOTKIT !!!
Service system32\drivers\SKYNETtidqomlw.sys (*** hidden *** ) [SYSTEM] SKYNETwnodrujf <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiibcjxvni@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiibcjxvni@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiibcjxvni@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiibcjxvni@imagepath \systemroot\system32\drivers\hjgruiwtpxjkji.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiibcjxvni\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiibcjxvni\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiibcjxvni\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiibcjxvni\
modules@hjgruirk.sys \systemroot\system32\drivers\hjgruiwtpxjkji.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiibcjxvni\
modules@hjgruicmd.dll \systemroot\system32\hjgruibapihxwp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf@imagepath \systemroot\system32\drivers\SKYNETtidqomlw.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\main@cmddelay 7200
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\
modules@SKYNETrk.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\
modules@SKYNETcmd.dll Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\
modules@SKYNETlog.dat \systemroot\system32\SKYNETaprqptkl.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\
modules@SKYNETwsp.dll Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETwnodrujf\
modules@SKYNET.dat \systemroot\system32\SKYNETlvrbwtnk.dat
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiibcjxvni@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiibcjxvni@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiibcjxvni@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiibcjxvni@imagepath \systemroot\system32\drivers\hjgruiwtpxjkji.sys
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiibcjxvni\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiibcjxvni\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiibcjxvni\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiibcjxvni\
modules@hjgruirk.sys \systemroot\system32\drivers\hjgruiwtpxjkji.sys
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiibcjxvni\
modules@hjgruicmd.dll \systemroot\system32\hjgruibapihxwp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf@imagepath \systemroot\system32\drivers\SKYNETtidqomlw.sys
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\main@aid 10096
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\main@cmddelay 7200
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\
modules@SKYNETrk.sys Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\
modules@SKYNETcmd.dll Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\
modules@SKYNETlog.dat \systemroot\system32\SKYNETaprqptkl.dat
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\
modules@SKYNETwsp.dll Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETwnodrujf\
modules@SKYNET.dat \systemroot\system32\SKYNETlvrbwtnk.dat
---- EOF - GMER 1.0.15 ----