• WELCOME
Welcome to the Myantispyware - free site offering help and assistance on spyware, malware and adware removal. As a guest you can only browse and view the various topics in the forums, but can not create a new topic and reply to an existing topic. If you are seeking help, you will need to be a logged into the forums with a registered account. Registering is free.
Click here to Create a free account and read How to use Spyware Removal Forum

Blocked opening all programs!

This forum is for removing Malware, Spyware, Adware. Post your HijackThis, DDS, RSIT, Combofix logs here.

Moderator: Moderators

Blocked opening all programs!

Postby Bradd » Sun Jul 25, 2010 1:38 pm

Here is the results from the log as you asked.


Logfile of random's system information tool 1.08 (written by random/random)
Run by Jordi at 2010-07-25 14:30:29
Microsoft Windows 7 Home Premium
System drive C: has 96 GB (68%) free of 143 GB
Total RAM: 3001 MB (71% free)

HijackThis download failed

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-10-20 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-12-01 2554680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.415.1646\swg.dll [2009-12-01 736240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-05 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHPN.dll [2010-04-15 2515552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-20 268816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-12-01 2554680]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{dd02a4eb-4afd-4d60-99d8-e67f964ca813} - PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHPN.dll [2010-04-15 2515552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-06 7600672]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-07-06 1833504]
"Acer ePower Management"=C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [2009-08-26 494112]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2009-01-21 156968]
"BackupManagerTray"=C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-04-11 249600]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2009-01-21 202024]
"EgisTecLiveUpdate"=C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe [2008-10-27 199464]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-25 30192]
"mwlDaemon"=C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2008-10-27 346672]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-12-26 173288]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2009-08-27 1194504]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-05 149280]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-06-03 135168]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-06-03 166912]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-06-03 143872]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
"snpstd3"=C:\Windows\vsnpstd3.exe [2006-09-19 827392]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-11-17 135168]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"vvnfcdxa"=C:\Users\Jordi\AppData\Local\mybqkuuva\aqihoxbtssd.exe [2010-07-25 312064]
"Tgukonegifop"=C:\Users\Jordi\AppData\Local\wshlmgrc.dll [2009-07-14 70144]
"Yxahenifij"=C:\Users\Jordi\AppData\Local\itibiqobacag.dll [2009-07-14 192000]
"setupupdate70700.exe"=C:\Users\Jordi\AppData\Roaming\1D0B0458FAB4EE3E8D598664B5E13C71\setupupdate70700.exe [2010-07-25 1051136]

C:\Users\Jordi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~1\GO36F4~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-06-03 215552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2009-10-20 219664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmd24.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmd24.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"legalnoticetext"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-07-25 14:30:29 ----D---- C:\rsit
2010-07-25 14:30:29 ----D---- C:\Program Files\trend micro
2010-07-25 14:24:10 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.24.10_log.txt
2010-07-25 14:23:43 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.23.43_log.txt
2010-07-25 14:23:38 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.23.38_log.txt
2010-07-25 14:21:22 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.22_log.txt
2010-07-25 14:21:18 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.18_log.txt
2010-07-25 14:21:14 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.14_log.txt
2010-07-25 14:21:02 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.02_log.txt
2010-07-25 14:20:55 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.20.55_log.txt
2010-07-25 14:20:41 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.20.41_log.txt
2010-07-25 04:40:52 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.40.52_log.txt
2010-07-25 04:36:51 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.51_log.txt
2010-07-25 04:36:41 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.41_log.txt
2010-07-25 04:36:26 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.26_log.txt
2010-07-25 04:36:17 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.17_log.txt
2010-07-25 04:35:55 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.35.55_log.txt
2010-07-25 04:35:39 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.35.39_log.txt
2010-07-25 04:28:26 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.28.26_log.txt
2010-07-25 04:27:17 ----D---- C:\Users\Jordi\AppData\Roaming\Malwarebytes
2010-07-25 04:26:47 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-07-25 04:26:46 ----D---- C:\ProgramData\Malwarebytes
2010-07-25 04:26:46 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-07-25 04:26:45 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-25 04:13:31 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.13.31_log.txt
2010-07-25 04:05:03 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.05.03_log.txt
2010-07-25 04:04:57 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.04.57_log.txt
2010-07-25 04:04:47 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.04.47_log.txt
2010-07-25 04:03:58 ----A---- C:\Windows\system32\drivers\klmd.sys
2010-07-25 04:03:58 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.03.58_log.txt
2010-07-25 03:06:15 ----A---- C:\Windows\system32\drivers\idmcubvg.sys
2010-07-25 03:02:36 ----D---- C:\Users\Jordi\AppData\Roaming\1D0B0458FAB4EE3E8D598664B5E13C71
2010-07-25 02:49:04 ----D---- C:\Users\Jordi\AppData\Roaming\DivX
2010-07-25 02:48:56 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-07-25 02:48:34 ----D---- C:\Program Files\Common Files\DivX Shared
2010-07-25 02:36:03 ----D---- C:\Program Files\DivX
2010-07-25 02:33:49 ----D---- C:\ProgramData\DivX
2010-07-23 04:30:51 ----D---- C:\Windows\system32\Adobe
2010-07-16 23:05:11 ----D---- C:\Program Files\RS2Botv2
2010-07-07 15:47:19 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-07-07 15:47:19 ----A---- C:\Windows\system32\PresentationHost.exe
2010-07-07 15:47:19 ----A---- C:\Windows\system32\netfxperf.dll
2010-07-07 15:47:19 ----A---- C:\Windows\system32\mscoree.dll
2010-07-07 15:47:18 ----A---- C:\Windows\system32\dfshim.dll
2010-07-06 17:21:53 ----A---- C:\Windows\system32\ntdll.dll
2010-07-06 17:21:53 ----A---- C:\Windows\system32\CPFilters.dll
2010-07-06 17:21:52 ----A---- C:\Windows\system32\msdri.dll
2010-07-06 17:08:31 ----A---- C:\Windows\system32\win32k.sys
2010-07-06 17:08:31 ----A---- C:\Windows\system32\asycfilt.dll
2010-07-06 17:08:30 ----A---- C:\Windows\system32\mshtml.dll
2010-07-06 17:08:29 ----A---- C:\Windows\system32\urlmon.dll
2010-07-06 17:08:29 ----A---- C:\Windows\system32\mstime.dll
2010-07-06 17:08:29 ----A---- C:\Windows\system32\ieframe.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\wininet.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\jsproxy.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\iedkcs32.dll

======List of files/folders modified in the last 1 months======

2010-07-25 14:30:29 ----RD---- C:\Program Files
2010-07-25 14:29:59 ----D---- C:\ProgramData\Kaspersky Lab
2010-07-25 14:29:55 ----D---- C:\Windows\Temp
2010-07-25 14:28:41 ----D---- C:\Windows\system32\config
2010-07-25 14:26:32 ----D---- C:\Windows\System32
2010-07-25 14:26:32 ----D---- C:\Windows\inf
2010-07-25 14:26:32 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-25 04:38:30 ----SHD---- C:\System Volume Information
2010-07-25 04:33:54 ----D---- C:\Windows\system32\drivers
2010-07-25 04:26:46 ----HD---- C:\ProgramData
2010-07-25 03:16:22 ----D---- C:\Windows\Prefetch
2010-07-25 02:48:56 ----D---- C:\Program Files\Common Files
2010-07-25 02:48:41 ----SHD---- C:\Windows\Installer
2010-07-25 02:48:41 ----SHD---- C:\Config.Msi
2010-07-25 02:38:27 ----D---- C:\Windows
2010-07-25 02:34:31 ----D---- C:\Windows\system32\Tasks
2010-07-23 04:30:52 ----D---- C:\Windows\Downloaded Program Files
2010-07-16 23:02:38 ----D---- C:\Windows\system32\NDF
2010-07-15 23:46:49 ----D---- C:\Windows\system32\catroot
2010-07-14 20:36:03 ----D---- C:\Windows\twain_32
2010-07-14 20:36:01 ----D---- C:\Windows\system32\catroot2
2010-07-14 20:36:00 ----D---- C:\Windows\system32\DriverStore
2010-07-07 16:24:53 ----D---- C:\Windows\Microsoft.NET
2010-07-07 16:24:50 ----RSD---- C:\Windows\assembly
2010-07-07 16:18:40 ----D---- C:\Windows\winsxs
2010-07-07 16:17:11 ----D---- C:\Windows\system32\migration
2010-07-07 16:17:11 ----D---- C:\Windows\ehome
2010-07-07 16:17:11 ----D---- C:\Program Files\Internet Explorer
2010-07-07 15:47:17 ----D---- C:\ProgramData\Microsoft Help
2010-07-07 15:45:06 ----D---- C:\Windows\AppPatch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 330264]
R0 klbg;Kaspersky Lab Boot Guard Driver; C:\Windows\system32\drivers\klbg.sys [2009-10-14 36880]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824]
R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2009-09-01 128016]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2010-05-31 311312]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2009-11-03 21520]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2008-10-09 19504]
R2 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2008-10-09 16432]
R2 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2008-10-09 59952]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-13 1035776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-07-13 1096704]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2009-03-26 21000]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-06-03 5915648]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-06 2657120]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2008-09-22 112128]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60x.sys [2008-09-04 223232]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2009-10-02 19472]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\Drivers\NTIDrvr.sys [2009-03-26 15360]
S1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2010-05-29 24856]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 klmd24;klmd24; C:\Windows\system32\drivers\klmd.sys [2010-07-25 69456]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-12-02 62976]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\Windows\system32\DRIVERS\snpstd3.sys [2007-03-27 10252544]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-12-18 75048]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-08-26 690720]
R2 MWLService;MyWinLocker Service; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2008-10-27 306736]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-04-11 61184]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-25 30192]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-01 138168]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-07 1343400]

-----------------EOF-----------------
And the second one named "info"

nfo.txt logfile of random's system information tool 1.08 2010-07-25 14:30:34

======Uninstall list======

-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\Setup.exe" -uninstall
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\Setup.exe" -uninstall
Acer Arcade Deluxe-->"C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" /z-uninstall
Acer Arcade Deluxe-->"C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" /z-uninstall
Acer Backup Manager-->C:\Program Files\InstallShield Installation Information\{72B776E5-4530-4C4B-9453-751DF87D9D93}\setup.exe -runfromtemp -l0x0409
Acer GridVista-->C:\Windows\GVUni.exe GridV.UNI
Acer PowerSmart Manager-->"C:\Program Files\InstallShield Installation Information\{3DB0448D-AD82-4923-B305-D001E521A964}\setup.exe" -runfromtemp -l0x0009 -removeonly
Acer Product Registration-->"C:\Program Files\InstallShield Installation Information\{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E}\setup.exe" -runfromtemp -l0x0009 -removeonly
Acer ScreenSaver-->C:\Windows\Screensavers\Acer\Uninstall.exe
Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Adobe Shockwave Player 11.5-->"C:\Windows\system32\Adobe\Shockwave 11\uninstaller.exe"
Agere Systems HDA Modem-->agrsmdel
Airport Mania First Flight-->"C:\Program Files\Acer GameZone\Airport Mania First Flight\Uninstall.exe" "C:\Program Files\Acer GameZone\Airport Mania First Flight\install.log"
ALPS Touch Pad Driver-->C:\Program Files\Apoint2K\Uninstap.exe ADDREMOVE
Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Broadcom Gigabit NetLink Controller-->MsiExec.exe /X{9AF0B106-56F1-461B-A270-95BC1682E282}
C:\Program Files\Acer GameZone\GameConsole-->"C:\Program Files\Acer GameZone\GameConsole\unins000.exe"
Cake Mania 2-->"C:\Program Files\Acer GameZone\Cake Mania 2\Uninstall.exe" "C:\Program Files\Acer GameZone\Cake Mania 2\install.log"
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Cooking Dash-->"C:\Program Files\Acer GameZone\Cooking Dash\Uninstall.exe" "C:\Program Files\Acer GameZone\Cooking Dash\install.log"
Cradle of Rome-->"C:\Program Files\Acer GameZone\Cradle of Rome\Uninstall.exe" "C:\Program Files\Acer GameZone\Cradle of Rome\install.log"
Dairy Dash-->"C:\Program Files\Acer GameZone\Dairy Dash\Uninstall.exe" "C:\Program Files\Acer GameZone\Dairy Dash\install.log"
DivX Setup-->C:\ProgramData\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com
Dream Day Honeymoon-->"C:\Program Files\Acer GameZone\Dream Day Honeymoon\Uninstall.exe" "C:\Program Files\Acer GameZone\Dream Day Honeymoon\install.log"
Driving Theory Test Express v2.6.0.0-->"C:\Program Files\Driving Theory Test Express\unins000.exe"
eSobi v2-->C:\Program Files\InstallShield Installation Information\{15D967B5-A4BE-42AE-9E84-64CD062B25AA}\setup.exe -runfromtemp -l0x0409
eSobi v2-->MsiExec.exe /X{15D967B5-A4BE-42AE-9E84-64CD062B25AA}
Galapago-->"C:\Program Files\Acer GameZone\Galapago\Uninstall.exe" "C:\Program Files\Acer GameZone\Galapago\install.log"
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
ImgBurn-->"C:\Program Files\ImgBurn\uninstall.exe"
Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Intel(R) TV Wizard-->C:\Windows\system32\TVWizudlg.exe -uninstall
iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
Jewel Quest Solitaire-->"C:\Program Files\Acer GameZone\Jewel Quest Solitaire\Uninstall.exe" "C:\Program Files\Acer GameZone\Jewel Quest Solitaire\install.log"
Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
Kaspersky Internet Security 2010-->MsiExec.exe /I{9D8B0949-7C47-476F-9F06-F900D3B078EA}
Launch Manager-->C:\Windows\UNINST32.EXE LManager.UNI
Luxor 2-->"C:\Program Files\Acer GameZone\Luxor 2\Uninstall.exe" "C:\Program Files\Acer GameZone\Luxor 2\install.log"
Mahjong Escape Ancient China-->"C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\Uninstall.exe" "C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\install.log"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (English)-->MsiExec.exe /X{95120000-00AF-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Suite Activation Assistant-->MsiExec.exe /X{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Works-->MsiExec.exe /I{67E03279-F703-408F-B4BF-46B5FC8D70CD}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MyWinLocker-->MsiExec.exe /X{68301905-2DEA-41CE-A4D4-E8B443B099BA}
NTI Backup Now 5-->C:\Program Files\InstallShield Installation Information\{12EFA1A4-AC3B-443C-8143-237EDE760403}\setup.exe -runfromtemp -l0x0409
NTI Media Maker 8-->C:\Program Files\InstallShield Installation Information\{2413930C-8309-47A6-BC61-5EF27A4222BC}\setup.exe -runfromtemp -l0x0409
Ocean Express-->"C:\Program Files\Acer GameZone\Ocean Express\Uninstall.exe" "C:\Program Files\Acer GameZone\Ocean Express\install.log"
Orion-->MsiExec.exe /X{5B63A470-9334-44D1-AF61-6CE2DB565AE9}
Parking Dash-->"C:\Program Files\Acer GameZone\Parking Dash\Uninstall.exe" "C:\Program Files\Acer GameZone\Parking Dash\install.log"
PHPNukeEN Toolbar-->C:\PROGRA~1\PHPNUK~1\UNWISE.EXE /U C:\PROGRA~1\PHPNUK~1\INSTALL.LOG
Pivot Stickfigure Animator-->MsiExec.exe /I{BEAD39CD-901D-4267-8B8B-EAA83CB4B70D}
Puzzle Express-->"C:\Program Files\Acer GameZone\Puzzle Express\Uninstall.exe" "C:\Program Files\Acer GameZone\Puzzle Express\install.log"
QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
Rainbow Web-->"C:\Program Files\Acer GameZone\Rainbow Web\Uninstall.exe" "C:\Program Files\Acer GameZone\Rainbow Web\install.log"
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Realtek USB 2.0 Card Reader-->C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\Setup.exe -runfromtemp -l0x0009 -removeonly
RS2Bot-->MsiExec.exe /I{3A02BF10-88B9-4D61-9439-A67C9DE7D4BC}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for 2007 Microsoft Office System (KB982312)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B0EC5722-241F-4CDA-83B4-AA5846B6F9F4}
Security Update for 2007 Microsoft Office System (KB982331)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E8766951-2B6C-4022-86E8-80D2D1762B76}
Security Update for Microsoft Office Excel 2007 (KB982308)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C3F9A0DC-A5D1-4BB6-870E-2953E5A2487B}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office PowerPoint 2007 (KB982158)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F5B70033-E79C-4569-90BF-BC9B4E4F3F46}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB982135)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0112C750-A06F-4F92-9C40-E5C1EA9A70EB}
Tradewinds 2-->"C:\Program Files\Acer GameZone\Tradewinds 2\Uninstall.exe" "C:\Program Files\Acer GameZone\Tradewinds 2\install.log"
Tri-Peaks Solitaire To Go-->"C:\Program Files\Acer GameZone\Tri-Peaks Solitaire To Go\Uninstall.exe" "C:\Program Files\Acer GameZone\Tri-Peaks Solitaire To Go\install.log"
Turbo Pizza-->"C:\Program Files\Acer GameZone\Turbo Pizza\Uninstall.exe" "C:\Program Files\Acer GameZone\Turbo Pizza\install.log"
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
Update for Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}
Update for Microsoft Office OneNote 2007 (KB980729)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {329050A9-EF80-40F9-B633-74508F54C1FF}
Update for Microsoft Office OneNote 2007 Help (KB963670)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2744EF05-38E1-4D5D-B333-E021EDAEA245}
Update for Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}
Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
Update for Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}
Upgrade Kit-->"C:\Program Files\InstallShield Installation Information\{1D0FDD6D-3C5E-4588-8ED0-02DC88014BF2}\setup.exe" -runfromtemp -l0x0009 -removeonly
VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
Wedding Dash-->"C:\Program Files\Acer GameZone\Wedding Dash\Uninstall.exe" "C:\Program Files\Acer GameZone\Wedding Dash\install.log"
Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}
Windows Live Mail-->MsiExec.exe /I{6412CECE-8172-4BE5-935B-6CECACD2CA87}
Windows Live Messenger-->MsiExec.exe /X{A85FD55B-891B-4314-97A5-EA96C0BD80B5}
Windows Live Photo Gallery-->MsiExec.exe /X{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}
Windows Live Sign-in Assistant-->MsiExec.exe /I{45338B07-A236-4270-9A77-EBB4115517B5}
Windows Live Sync-->MsiExec.exe /X{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}
Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Windows Live Writer-->MsiExec.exe /X{178832DE-9DE0-4C87-9F82-9315A9B03985}
Zuma Deluxe-->"C:\Program Files\Acer GameZone\Zuma Deluxe\Uninstall.exe" "C:\Program Files\Acer GameZone\Zuma Deluxe\install.log"

======System event log======

Computer Name: Jordi-PC
Event Code: 4001
Message: WLAN AutoConfig service has successfully stopped.

Record Number: 20901
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20091225233204.367231-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: Jordi-PC
Event Code: 1014
Message: Name resolution for the name local-bay.contacts.msn.com timed out after none of the configured DNS servers responded.
Record Number: 20865
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20091225231137.701870-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE

Computer Name: Jordi-PC
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 20852
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20091225223625.142415-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE

Computer Name: Jordi-PC
Event Code: 1014
Message: Name resolution for the name wpad.home timed out after none of the configured DNS servers responded.
Record Number: 20833
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20091225215851.613362-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE

Computer Name: Jordi-PC
Event Code: 1014
Message: Name resolution for the name static5.flixster.com timed out after none of the configured DNS servers responded.
Record Number: 20821
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20091225212032.904685-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE

=====Application event log=====

Computer Name: Jordi-PC
Event Code: 33
Message: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksCal.exe". Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found. Please use sxstrace.exe for detailed diagnosis.
Record Number: 1054
Source Name: SideBySide
Time Written: 20091201171448.000000-000
Event Type: Error
User:

Computer Name: Jordi-PC
Event Code: 8194
Message: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005. This is often caused by incorrect security settings in either the writer or requestor process.

Operation:
Gathering Writer Data

Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {da8a3f86-4858-4d69-9a3b-720b64c22851}
Record Number: 1050
Source Name: VSS
Time Written: 20091201171410.000000-000
Event Type: Error
User:

Computer Name: Jordi-PC
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 1027
Source Name: Microsoft-Windows-WMI
Time Written: 20091201171245.000000-000
Event Type: Error
User:

Computer Name: Jordi-PC
Event Code: 1008
Message:
Record Number: 1020
Source Name: Microsoft-Windows-Search
Time Written: 20091201171235.000000-000
Event Type: Warning
User:

Computer Name: WIN-115C34GTQZR
Event Code: 1530
Message:
Record Number: 1012
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090623040747.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

=====Security event log=====

Computer Name: Jordi-PC
Event Code: 4634
Message: An account was logged off.

Subject:
Security ID: S-1-5-7
Account Name: ANONYMOUS LOGON
Account Domain: NT AUTHORITY
Logon ID: 0x20dd7

Logon Type: 3

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
Record Number: 1287
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090623040748.124200-000
Event Type: Audit Success
User:

Computer Name: WIN-115C34GTQZR
Event Code: 4616
Message: The system time was changed.

Subject:
Security ID: S-1-5-19
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3e5

Process Information:
Process ID: 0x4f0
Name: C:\Windows\System32\svchost.exe

Previous Time: 05:07:47 23/06/2009
New Time: 05:07:47 23/06/2009

This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer.
Record Number: 1286
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090623040747.937000-000
Event Type: Audit Success
User:

Computer Name: WIN-115C34GTQZR
Event Code: 4647
Message: User initiated logoff:

Subject:
Security ID: S-1-5-21-2206892437-2735258362-4033050996-500
Account Name: Administrator
Account Domain: WIN-115C34GTQZR
Logon ID: 0x2b0e2

This event is generated when a logoff is initiated. No further user-initiated activity can occur. This event can be interpreted as a logoff event.
Record Number: 1285
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090623040747.406815-000
Event Type: Audit Success
User:

Computer Name: WIN-115C34GTQZR
Event Code: 1100
Message: The event logging service has shut down.
Record Number: 1284
Source Name: Microsoft-Windows-Eventlog
Time Written: 20090623040748.046200-000
Event Type: Audit Success
User:

Computer Name: WIN-115C34GTQZR
Event Code: 1102
Message: The audit log was cleared.
Subject:
Security ID: S-1-5-21-2206892437-2735258362-4033050996-500
Account Name: Administrator
Domain Name: WIN-115C34GTQZR
Logon ID: 0x2b0e2
Record Number: 1283
Source Name: Microsoft-Windows-Eventlog
Time Written: 20090623040616.942415-000
Event Type: Audit Success
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"DFSTRACINGON"=FALSE
"NTIPath"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\;
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\EgisTec\MyWinLocker 3\x86;C:\Program Files\EgisTec\MyWinLocker 3\x64;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\QuickTime\QTSystem\
"Pathtem"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

-----------------EOF-----------------
Bradd
 
Posts: 4
Joined: Sun Jul 25, 2010 1:33 pm

Re: Blocked opening all programs!

Postby patrik » Sun Jul 25, 2010 1:54 pm

Hello, welcome to the Myantispyware forum.

Please download OTM by OldTimer from here, but before saving, rename otm.exe to iexplore.exe
Run OTM, copy,then paste the following text in "Paste Instructions for Items to be Moved" window (under the yellow bar):
Code: Select all
:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"vvnfcdxa"=-
"Tgukonegifop"=-
"Yxahenifij"=-
"setupupdate70700.exe"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"=-

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmd24.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmd24.sys]

:files
C:\Users\Jordi\AppData\Roaming\1D0B0458FAB4EE3E8D598664B5E13C71
C:\Users\Jordi\AppData\Local\itibiqobacag.dll
C:\Users\Jordi\AppData\Local\wshlmgrc.dll
C:\Users\Jordi\AppData\Local\mybqkuuva

:Commands
[emptytemp]
[Reboot]

Click the red Moveit! button. When the tool is finished, it will produce a report for you. If you are asked to reboot the machine choose Yes. Afterwards, Windows restarts, and opens the log generated by the OTM so you can see the results. Save the log to your desktop.
Note: If it does not automatically open, then click Start -> Run, type notepad and press Enter. Click File -> Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present.

Post back with OTM log + fresh RSIT log.
patrik
Site Admin
 
Posts: 8628
Joined: Sun Jan 08, 2006 1:11 pm

Re: Blocked opening all programs!

Postby Bradd » Sun Jul 25, 2010 2:31 pm

Here is the fresh Rsit Log


Logfile of random's system information tool 1.08 (written by random/random)
Run by Jordi at 2010-07-25 15:29:10
Microsoft Windows 7 Home Premium
System drive C: has 96 GB (67%) free of 143 GB
Total RAM: 3001 MB (75% free)

HijackThis download failed

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-10-20 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-12-01 2554680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.415.1646\swg.dll [2009-12-01 736240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-05 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHPN.dll [2010-04-15 2515552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-20 268816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-12-01 2554680]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{dd02a4eb-4afd-4d60-99d8-e67f964ca813} - PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHPN.dll [2010-04-15 2515552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-06 7600672]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-07-06 1833504]
"Acer ePower Management"=C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [2009-08-26 494112]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2009-01-21 156968]
"BackupManagerTray"=C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-04-11 249600]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2009-01-21 202024]
"EgisTecLiveUpdate"=C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe [2008-10-27 199464]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-25 30192]
"mwlDaemon"=C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2008-10-27 346672]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-12-26 173288]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2009-08-27 1194504]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-05 149280]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-06-03 135168]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-06-03 166912]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-06-03 143872]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
"snpstd3"=C:\Windows\vsnpstd3.exe [2006-09-19 827392]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-11-17 135168]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"Tgukonegifop"=C:\Users\Jordi\AppData\Local\wshlmgrc.dll,Startup []
"Yxahenifij"=C:\Users\Jordi\AppData\Local\itibiqobacag.dll,Startup []

C:\Users\Jordi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~1\GO36F4~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-06-03 215552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2009-10-20 219664]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"legalnoticetext"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-07-25 15:24:10 ----D---- C:\_OTM
2010-07-25 14:44:37 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.44.37_log.txt
2010-07-25 14:30:29 ----D---- C:\rsit
2010-07-25 14:30:29 ----D---- C:\Program Files\trend micro
2010-07-25 14:24:10 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.24.10_log.txt
2010-07-25 14:23:43 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.23.43_log.txt
2010-07-25 14:23:38 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.23.38_log.txt
2010-07-25 14:21:22 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.22_log.txt
2010-07-25 14:21:18 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.18_log.txt
2010-07-25 14:21:14 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.14_log.txt
2010-07-25 14:21:02 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.02_log.txt
2010-07-25 14:20:55 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.20.55_log.txt
2010-07-25 14:20:41 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.20.41_log.txt
2010-07-25 04:40:52 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.40.52_log.txt
2010-07-25 04:36:51 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.51_log.txt
2010-07-25 04:36:41 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.41_log.txt
2010-07-25 04:36:26 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.26_log.txt
2010-07-25 04:36:17 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.17_log.txt
2010-07-25 04:35:55 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.35.55_log.txt
2010-07-25 04:35:39 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.35.39_log.txt
2010-07-25 04:28:26 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.28.26_log.txt
2010-07-25 04:27:17 ----D---- C:\Users\Jordi\AppData\Roaming\Malwarebytes
2010-07-25 04:26:47 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-07-25 04:26:46 ----D---- C:\ProgramData\Malwarebytes
2010-07-25 04:26:46 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-07-25 04:26:45 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-25 04:13:31 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.13.31_log.txt
2010-07-25 04:05:03 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.05.03_log.txt
2010-07-25 04:04:57 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.04.57_log.txt
2010-07-25 04:04:47 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.04.47_log.txt
2010-07-25 04:03:58 ----A---- C:\Windows\system32\drivers\klmd.sys
2010-07-25 04:03:58 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.03.58_log.txt
2010-07-25 03:06:15 ----A---- C:\Windows\system32\drivers\idmcubvg.sys
2010-07-25 02:49:04 ----D---- C:\Users\Jordi\AppData\Roaming\DivX
2010-07-25 02:48:56 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-07-25 02:48:34 ----D---- C:\Program Files\Common Files\DivX Shared
2010-07-25 02:36:03 ----D---- C:\Program Files\DivX
2010-07-25 02:33:49 ----D---- C:\ProgramData\DivX
2010-07-23 04:30:51 ----D---- C:\Windows\system32\Adobe
2010-07-16 23:05:11 ----D---- C:\Program Files\RS2Botv2
2010-07-07 15:47:19 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-07-07 15:47:19 ----A---- C:\Windows\system32\PresentationHost.exe
2010-07-07 15:47:19 ----A---- C:\Windows\system32\netfxperf.dll
2010-07-07 15:47:19 ----A---- C:\Windows\system32\mscoree.dll
2010-07-07 15:47:18 ----A---- C:\Windows\system32\dfshim.dll
2010-07-06 17:21:53 ----A---- C:\Windows\system32\ntdll.dll
2010-07-06 17:21:53 ----A---- C:\Windows\system32\CPFilters.dll
2010-07-06 17:21:52 ----A---- C:\Windows\system32\msdri.dll
2010-07-06 17:08:31 ----A---- C:\Windows\system32\win32k.sys
2010-07-06 17:08:31 ----A---- C:\Windows\system32\asycfilt.dll
2010-07-06 17:08:30 ----A---- C:\Windows\system32\mshtml.dll
2010-07-06 17:08:29 ----A---- C:\Windows\system32\urlmon.dll
2010-07-06 17:08:29 ----A---- C:\Windows\system32\mstime.dll
2010-07-06 17:08:29 ----A---- C:\Windows\system32\ieframe.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\wininet.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\jsproxy.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\iedkcs32.dll

======List of files/folders modified in the last 1 months======

2010-07-25 15:25:21 ----D---- C:\ProgramData\Kaspersky Lab
2010-07-25 15:25:18 ----D---- C:\Windows\Temp
2010-07-25 15:24:19 ----D---- C:\Windows\system32\config
2010-07-25 15:03:40 ----D---- C:\Windows\System32
2010-07-25 15:03:40 ----D---- C:\Windows\inf
2010-07-25 15:03:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-25 14:30:29 ----RD---- C:\Program Files
2010-07-25 04:38:30 ----SHD---- C:\System Volume Information
2010-07-25 04:33:54 ----D---- C:\Windows\system32\drivers
2010-07-25 04:26:46 ----HD---- C:\ProgramData
2010-07-25 03:16:22 ----D---- C:\Windows\Prefetch
2010-07-25 02:48:56 ----D---- C:\Program Files\Common Files
2010-07-25 02:48:41 ----SHD---- C:\Windows\Installer
2010-07-25 02:48:41 ----SHD---- C:\Config.Msi
2010-07-25 02:38:27 ----D---- C:\Windows
2010-07-25 02:34:31 ----D---- C:\Windows\system32\Tasks
2010-07-23 04:30:52 ----D---- C:\Windows\Downloaded Program Files
2010-07-16 23:02:38 ----D---- C:\Windows\system32\NDF
2010-07-15 23:46:49 ----D---- C:\Windows\system32\catroot
2010-07-14 20:36:03 ----D---- C:\Windows\twain_32
2010-07-14 20:36:01 ----D---- C:\Windows\system32\catroot2
2010-07-14 20:36:00 ----D---- C:\Windows\system32\DriverStore
2010-07-07 16:24:53 ----D---- C:\Windows\Microsoft.NET
2010-07-07 16:24:50 ----RSD---- C:\Windows\assembly
2010-07-07 16:18:40 ----D---- C:\Windows\winsxs
2010-07-07 16:17:11 ----D---- C:\Windows\system32\migration
2010-07-07 16:17:11 ----D---- C:\Windows\ehome
2010-07-07 16:17:11 ----D---- C:\Program Files\Internet Explorer
2010-07-07 15:47:17 ----D---- C:\ProgramData\Microsoft Help
2010-07-07 15:45:06 ----D---- C:\Windows\AppPatch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 330264]
R0 klbg;Kaspersky Lab Boot Guard Driver; C:\Windows\system32\drivers\klbg.sys [2009-10-14 36880]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824]
R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2009-09-01 128016]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2010-05-31 311312]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2009-11-03 21520]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2008-10-09 19504]
R2 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2008-10-09 16432]
R2 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2008-10-09 59952]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-13 1035776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-07-13 1096704]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2009-03-26 21000]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-06-03 5915648]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-06 2657120]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2008-09-22 112128]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60x.sys [2008-09-04 223232]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2009-10-02 19472]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\Drivers\NTIDrvr.sys [2009-03-26 15360]
S1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2010-05-29 24856]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-12-02 62976]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\Windows\system32\DRIVERS\snpstd3.sys [2007-03-27 10252544]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-12-18 75048]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-08-26 690720]
R2 MWLService;MyWinLocker Service; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2008-10-27 306736]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-04-11 61184]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-25 30192]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-01 138168]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-07 1343400]

-----------------EOF-----------------
Here is the OTM Log

========== SERVICES/DRIVERS ==========
Service klmd24 stopped successfully!
Service klmd24 deleted successfully!
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vvnfcdxa deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Tgukonegifop deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Yxahenifij deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\setupupdate70700.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmd24.sys\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmd24.sys\ deleted successfully.
========== FILES ==========
C:\Users\Jordi\AppData\Roaming\1D0B0458FAB4EE3E8D598664B5E13C71 folder moved successfully.
DllUnregisterServer procedure not found in C:\Users\Jordi\AppData\Local\itibiqobacag.dll
C:\Users\Jordi\AppData\Local\itibiqobacag.dll moved successfully.
DllUnregisterServer procedure not found in C:\Users\Jordi\AppData\Local\wshlmgrc.dll
C:\Users\Jordi\AppData\Local\wshlmgrc.dll moved successfully.
C:\Users\Jordi\AppData\Local\mybqkuuva folder moved successfully.
========== COMMANDS ==========

OTM by OldTimer - Version 3.1.15.0 log created on 07252010_152410
Bradd
 
Posts: 4
Joined: Sun Jul 25, 2010 1:33 pm

Re: Blocked opening all programs!

Postby patrik » Sun Jul 25, 2010 2:36 pm

Download and install Malwarebytes Anti-malware (MBAM).
Run, perform Quick Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad (save the log to your desktop) and you may be prompted to Restart.

Post back with MBAM log + fresh RSIT log.
patrik
Site Admin
 
Posts: 8628
Joined: Sun Jan 08, 2006 1:11 pm

Re: Blocked opening all programs!

Postby Bradd » Sun Jul 25, 2010 2:46 pm

I've ran the TDSS KILLER and also the Malwarebytes and got rid of the problem, however now i can't access the internet?
MBAM LOG
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

25/07/2010 15:42:22
mbam-log-2010-07-25 (15-42-22).txt

Scan type: Quick scan
Objects scanned: 119591
Time elapsed: 6 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tgukonegifop (Trojan.Agent.U) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yxahenifij (Trojan.Agent.U) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Fresh rsit log

Logfile of random's system information tool 1.08 (written by random/random)
Run by Jordi at 2010-07-25 15:48:35
Microsoft Windows 7 Home Premium
System drive C: has 96 GB (67%) free of 143 GB
Total RAM: 3001 MB (73% free)

HijackThis download failed

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll [2009-10-20 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-12-01 2554680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.415.1646\swg.dll [2009-12-01 736240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-05 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHPN.dll [2010-04-15 2515552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll [2009-10-20 268816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-12-01 2554680]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{dd02a4eb-4afd-4d60-99d8-e67f964ca813} - PHPNukeEN Toolbar - C:\Program Files\PHPNukeEN\tbPHPN.dll [2010-04-15 2515552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-06 7600672]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-07-06 1833504]
"Acer ePower Management"=C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [2009-08-26 494112]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2009-01-21 156968]
"BackupManagerTray"=C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-04-11 249600]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2009-01-21 202024]
"EgisTecLiveUpdate"=C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe [2008-10-27 199464]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-25 30192]
"mwlDaemon"=C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2008-10-27 346672]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-12-26 173288]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2009-08-27 1194504]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-05 149280]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-06-03 135168]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-06-03 166912]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-06-03 143872]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
"snpstd3"=C:\Windows\vsnpstd3.exe [2006-09-19 827392]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-11-17 135168]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]

C:\Users\Jordi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~1\GO36F4~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-06-03 215552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2009-10-20 219664]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmd24.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmd24.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"legalnoticetext"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-07-25 15:33:31 ----A---- C:\Windows\system32\drivers\klmdb.sys
2010-07-25 15:32:10 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_15.32.10_log.txt
2010-07-25 15:24:10 ----D---- C:\_OTM
2010-07-25 14:44:37 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.44.37_log.txt
2010-07-25 14:30:29 ----D---- C:\rsit
2010-07-25 14:30:29 ----D---- C:\Program Files\trend micro
2010-07-25 14:24:10 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.24.10_log.txt
2010-07-25 14:23:43 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.23.43_log.txt
2010-07-25 14:23:38 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.23.38_log.txt
2010-07-25 14:21:22 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.22_log.txt
2010-07-25 14:21:18 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.18_log.txt
2010-07-25 14:21:14 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.14_log.txt
2010-07-25 14:21:02 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.21.02_log.txt
2010-07-25 14:20:55 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.20.55_log.txt
2010-07-25 14:20:41 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_14.20.41_log.txt
2010-07-25 04:40:52 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.40.52_log.txt
2010-07-25 04:36:51 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.51_log.txt
2010-07-25 04:36:41 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.41_log.txt
2010-07-25 04:36:26 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.26_log.txt
2010-07-25 04:36:17 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.36.17_log.txt
2010-07-25 04:35:55 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.35.55_log.txt
2010-07-25 04:35:39 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.35.39_log.txt
2010-07-25 04:28:26 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.28.26_log.txt
2010-07-25 04:27:17 ----D---- C:\Users\Jordi\AppData\Roaming\Malwarebytes
2010-07-25 04:26:47 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-07-25 04:26:46 ----D---- C:\ProgramData\Malwarebytes
2010-07-25 04:26:46 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-07-25 04:26:45 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-25 04:13:31 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.13.31_log.txt
2010-07-25 04:05:03 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.05.03_log.txt
2010-07-25 04:04:57 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.04.57_log.txt
2010-07-25 04:04:47 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.04.47_log.txt
2010-07-25 04:03:58 ----A---- C:\Windows\system32\drivers\klmd.sys
2010-07-25 04:03:58 ----A---- C:\TDSSKiller.2.4.0.0_25.07.2010_04.03.58_log.txt
2010-07-25 03:06:15 ----A---- C:\Windows\system32\drivers\idmcubvg.sys
2010-07-25 02:49:04 ----D---- C:\Users\Jordi\AppData\Roaming\DivX
2010-07-25 02:48:56 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-07-25 02:48:34 ----D---- C:\Program Files\Common Files\DivX Shared
2010-07-25 02:36:03 ----D---- C:\Program Files\DivX
2010-07-25 02:33:49 ----D---- C:\ProgramData\DivX
2010-07-23 04:30:51 ----D---- C:\Windows\system32\Adobe
2010-07-16 23:05:11 ----D---- C:\Program Files\RS2Botv2
2010-07-07 15:47:19 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-07-07 15:47:19 ----A---- C:\Windows\system32\PresentationHost.exe
2010-07-07 15:47:19 ----A---- C:\Windows\system32\netfxperf.dll
2010-07-07 15:47:19 ----A---- C:\Windows\system32\mscoree.dll
2010-07-07 15:47:18 ----A---- C:\Windows\system32\dfshim.dll
2010-07-06 17:21:53 ----A---- C:\Windows\system32\ntdll.dll
2010-07-06 17:21:53 ----A---- C:\Windows\system32\CPFilters.dll
2010-07-06 17:21:52 ----A---- C:\Windows\system32\msdri.dll
2010-07-06 17:08:31 ----A---- C:\Windows\system32\win32k.sys
2010-07-06 17:08:31 ----A---- C:\Windows\system32\asycfilt.dll
2010-07-06 17:08:30 ----A---- C:\Windows\system32\mshtml.dll
2010-07-06 17:08:29 ----A---- C:\Windows\system32\urlmon.dll
2010-07-06 17:08:29 ----A---- C:\Windows\system32\mstime.dll
2010-07-06 17:08:29 ----A---- C:\Windows\system32\ieframe.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\wininet.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\jsproxy.dll
2010-07-06 17:08:28 ----A---- C:\Windows\system32\iedkcs32.dll

======List of files/folders modified in the last 1 months======

2010-07-25 15:45:55 ----D---- C:\Windows\Temp
2010-07-25 15:44:11 ----D---- C:\Windows\system32\NDF
2010-07-25 15:41:40 ----D---- C:\Windows\System32
2010-07-25 15:41:40 ----D---- C:\Windows\inf
2010-07-25 15:41:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-25 15:34:49 ----D---- C:\ProgramData\Kaspersky Lab
2010-07-25 15:34:18 ----D---- C:\Windows\Minidump
2010-07-25 15:34:14 ----D---- C:\Windows
2010-07-25 15:33:31 ----D---- C:\Windows\system32\drivers
2010-07-25 15:24:19 ----D---- C:\Windows\system32\config
2010-07-25 14:30:29 ----RD---- C:\Program Files
2010-07-25 04:38:30 ----SHD---- C:\System Volume Information
2010-07-25 04:26:46 ----HD---- C:\ProgramData
2010-07-25 03:16:22 ----D---- C:\Windows\Prefetch
2010-07-25 02:48:56 ----D---- C:\Program Files\Common Files
2010-07-25 02:48:41 ----SHD---- C:\Windows\Installer
2010-07-25 02:48:41 ----SHD---- C:\Config.Msi
2010-07-25 02:34:31 ----D---- C:\Windows\system32\Tasks
2010-07-23 04:30:52 ----D---- C:\Windows\Downloaded Program Files
2010-07-15 23:46:49 ----D---- C:\Windows\system32\catroot
2010-07-14 20:36:03 ----D---- C:\Windows\twain_32
2010-07-14 20:36:01 ----D---- C:\Windows\system32\catroot2
2010-07-14 20:36:00 ----D---- C:\Windows\system32\DriverStore
2010-07-07 16:24:53 ----D---- C:\Windows\Microsoft.NET
2010-07-07 16:24:50 ----RSD---- C:\Windows\assembly
2010-07-07 16:18:40 ----D---- C:\Windows\winsxs
2010-07-07 16:17:11 ----D---- C:\Windows\system32\migration
2010-07-07 16:17:11 ----D---- C:\Windows\ehome
2010-07-07 16:17:11 ----D---- C:\Program Files\Internet Explorer
2010-07-07 15:47:17 ----D---- C:\ProgramData\Microsoft Help
2010-07-07 15:45:06 ----D---- C:\Windows\AppPatch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 330264]
R0 klbg;Kaspersky Lab Boot Guard Driver; C:\Windows\system32\drivers\klbg.sys [2009-10-14 36880]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824]
R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2009-09-01 128016]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2010-05-31 311312]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2009-11-03 21520]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2008-10-09 19504]
R2 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2008-10-09 16432]
R2 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2008-10-09 59952]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2009-07-13 1035776]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-07-13 1096704]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2009-03-26 21000]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-06-03 5915648]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-06 2657120]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2008-09-22 112128]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60x.sys [2008-09-04 223232]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2009-10-02 19472]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\Drivers\NTIDrvr.sys [2009-03-26 15360]
S0 klmdb;klmdb; C:\Windows\system32\drivers\klmdb.sys [2010-07-25 69456]
S1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2010-05-29 24856]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 klmd24;klmd24; C:\Windows\system32\drivers\klmd.sys [2010-07-25 69456]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-12-02 62976]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\Windows\system32\DRIVERS\snpstd3.sys [2007-03-27 10252544]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340456]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-12-18 75048]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-08-26 690720]
R2 MWLService;MyWinLocker Service; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2008-10-27 306736]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-04-11 61184]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-25 30192]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-01 138168]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-07 1343400]

-----------------EOF-----------------
Bradd
 
Posts: 4
Joined: Sun Jul 25, 2010 1:33 pm

Re: Blocked opening all programs!

Postby patrik » Sun Jul 25, 2010 3:03 pm

however now i can't access the internet?

Now you can`t open any site ? What you see when trying it ?
patrik
Site Admin
 
Posts: 8628
Joined: Sun Jan 08, 2006 1:11 pm

Re: Blocked opening all programs!

Postby Bradd » Sun Jul 25, 2010 3:05 pm

It says internet explorer can not display the webpage. Then when i diagnose the problem it says "The remote device or resource won't accept the connection"
Bradd
 
Posts: 4
Joined: Sun Jul 25, 2010 1:33 pm

Re: Blocked opening all programs!

Postby patrik » Mon Jul 26, 2010 5:21 pm

Run Internet Explorer, Click Tools -> Internet Options. Select Connections Tab and click to Lan Settings button. Uncheck “Use a proxy server” box. Click OK. Click OK.

Try to open any site.
patrik
Site Admin
 
Posts: 8628
Joined: Sun Jan 08, 2006 1:11 pm


Return to Spyware Removal

Who is online

Users browsing this forum: No registered users and 1 guest