Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Please help with debug virus adware/spyware
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Please help with debug virus adware/spyware  
Forum Quick Jump
 
New Topic Post reply to : Please help with debug virus adware/spyware Printable version of : Please help with debug virus adware/spyware
[ << Previous Thread | Next Thread >> ]

Maika
New Member


Date Joined Sep 2008
Total Posts : 4
 
   Posted 9-3-2008 7:03 (GMT +1)    Quote: Please help with debug virus adware/spywareAlert an admin about: Please help with debug virus adware/spyware
I've done all the prep by following your guidelines posted on here for virus removal. Here are my logs. Please advise me on what to I need to delete. confused  Thanks! Your help is truly appreciated!
 
ComboFix 08-09-01.04 - Maika 2008-09-03  0:21:06.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.993 [GMT -5:00]
Running from: C:\Documents and Settings\Maika\Desktop\ComboFix.exe
 * Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Secure Solutions
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080805113943734.log
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080805114518390.log
C:\Documents and Settings\Tay\Application Data\macromedia\Flash Player\#SharedObjects\C8Z2UE7H\bin.clearspring.com
C:\Documents and Settings\Tay\Application Data\macromedia\Flash Player\#SharedObjects\C8Z2UE7H\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Tay\Application Data\macromedia\Flash Player\#SharedObjects\C8Z2UE7H\interclick.com
C:\Documents and Settings\Tay\Application Data\macromedia\Flash Player\#SharedObjects\C8Z2UE7H\interclick.com\ud.sol
C:\Documents and Settings\Tay\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Tay\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Tay\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Tay\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Tay\Desktop\Privacy Protector.url
C:\Documents and Settings\Victoria\Application Data\macromedia\Flash Player\#SharedObjects\Q9ARPGHC\interclick.com
C:\Documents and Settings\Victoria\Application Data\macromedia\Flash Player\#SharedObjects\Q9ARPGHC\interclick.com\ud.sol
C:\Documents and Settings\Victoria\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Victoria\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Victoria\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\jestertb.dll
.
(((((((((((((((((((((((((   Files Created from 2008-08-03 to 2008-09-03  )))))))))))))))))))))))))))))))
.
2008-09-02 23:01 . 2008-09-02 23:01 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-02 23:01 . 2008-09-02 23:01 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\SUPERAntiSpyware.com
2008-09-02 23:01 . 2008-09-02 23:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-02 23:00 . 2008-09-02 23:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-02 22:53 . 2008-09-02 22:53 <DIR> d-------- C:\Program Files\CCleaner
2008-09-02 21:32 . 2008-04-13 19:12 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-02 20:17 . 2008-09-02 20:17 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-02 19:51 . 2004-08-04 05:00 10,457 -----c--- C:\WINDOWS\system32\dllcache\wmptour.hta
2008-09-02 19:51 . 2004-08-04 05:00 1,771 -----c--- C:\WINDOWS\system32\dllcache\wmptour.css
2008-09-02 19:51 . 2004-08-04 05:00 855 -----c--- C:\WINDOWS\system32\dllcache\wmpocm.inf
2008-09-02 19:51 . 2004-08-04 05:00 420 -----c--- C:\WINDOWS\system32\dllcache\wmploc.js
2008-09-02 19:49 . 2004-08-04 05:00 300,969 -----c--- C:\WINDOWS\system32\dllcache\viz.wmv
2008-09-02 19:48 . 2008-04-13 19:12 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-09-02 19:47 . 2008-04-13 19:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-09-02 19:46 . 2008-04-13 19:12 380,416 --a------ C:\WINDOWS\system32\irprops.cpl
2008-09-02 19:45 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-09-02 19:44 . 2008-04-13 19:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-09-02 12:54 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-02 12:54 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-02 10:45 . 2008-09-02 10:51 2,855 --a------ C:\WINDOWS\svchost.PIF
2008-09-02 10:42 . 2008-09-02 10:42 <DIR> d--h----- C:\WINDOWS\PIF
2008-09-02 10:28 . 2008-09-02 10:28 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-09-02 10:13 . 2008-09-03 00:21 <DIR> d-------- C:\QUARANTINE
2008-09-02 10:10 . 2008-09-02 10:10 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-09-02 10:10 . 2008-09-02 10:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-02 10:10 . 2006-11-17 03:06 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2008-09-02 10:10 . 2006-11-17 03:06 280 --a------ C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-09-02 10:09 . 2008-09-02 10:10 <DIR> d-------- C:\Program Files\McAfee
2008-09-02 10:09 . 2008-09-02 10:09 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-09-02 10:09 . 2006-11-30 08:50 168,776 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-09-02 10:09 . 2006-11-30 08:50 72,264 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-09-02 10:09 . 2006-11-30 08:50 64,360 --a------ C:\WINDOWS\system32\drivers\mfeapfk.sys
2008-09-02 10:09 . 2006-11-30 08:50 52,136 --a------ C:\WINDOWS\system32\drivers\mfetdik.sys
2008-09-02 10:09 . 2006-11-30 08:50 34,152 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-09-02 06:21 . 2008-09-02 06:23 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-09-02 06:21 . 2008-09-02 06:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-31 19:16 . 2008-08-31 22:17 <DIR> d-------- C:\Documents and Settings\Victoria\Application Data\COMCASTTOOLBAR
2008-08-31 01:24 . 2008-08-31 22:04 62,464 --a------ C:\Program Files\wsv.exe
2008-08-29 00:50 . 2008-08-29 00:55 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-08-29 00:50 . 2008-08-29 00:50 <DIR> d-------- C:\Program Files\ComcastToolbar
2008-08-29 00:50 . 2008-09-03 00:19 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\ComcastToolbar
2008-08-29 00:45 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-29 00:41 . 2008-08-29 00:41 <DIR> d-------- C:\Program Files\Viewpoint
2008-08-29 00:41 . 2008-08-29 00:41 <DIR> d-------- C:\Program Files\SigmaTel
2008-08-29 00:41 . 2008-08-29 00:41 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\Runaware
2008-08-29 00:36 . 2008-08-29 00:36 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-08-05 12:16 . 2008-08-05 12:18 <DIR> d-------- C:\WINDOWS\privacy_danger(2)
2008-08-05 11:57 . 2008-08-05 11:57 <DIR> d-------- C:\WINDOWS\McAfee.com
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-02 15:56 --------- d-----w C:\Program Files\SuperStar
2008-08-29 05:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-17 19:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-11 18:26 --------- d-----w C:\Documents and Settings\Victoria\Application Data\dvdcss
2008-08-08 05:56 --------- d-----w C:\Program Files\PokerStars
2008-08-03 21:38 --------- d-----w C:\Documents and Settings\Maika\Application Data\dvdcss
2008-07-26 04:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-07-20 22:55 --------- d-----w C:\Program Files\INVENT
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es(2)(3).dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-06 17:11 --------- d-----w C:\Program Files\Common Files\xing shared
2008-07-06 17:11 --------- d-----w C:\Program Files\Common Files\Real
2008-07-06 17:10 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-06 17:10 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-07-06 17:10 --------- d-----w C:\Program Files\Real
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet(3)(2).dll
2008-06-23 16:57 267,776 ----a-w C:\WINDOWS\system32\iertutil(2)(3).dll
2008-06-23 16:57 105,984 ----a-w C:\WINDOWS\system32\url(3)(2).dll
2008-06-23 16:57 1,159,680 ----a-w C:\WINDOWS\system32\urlmon(3)(2).dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-07-28 05:46 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 223984]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-08-19 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 223984]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 176128]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-07-06 185896]
"YMailAdvisor"="C:\Program Files\Yahoo!\Common\YMailAdvisor.exe" [2008-06-05 125208]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 C:\WINDOWS\system32\bthprops.cpl]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 1724416]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-04-05 11:26 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 GoToAssist;GoToAssist;C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe Start=service [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4eafb541-f1cd-11dc-9e5b-806d6172696f}]
\Shell\AutoRun\command - F:\launcher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77230a70-205f-11dd-9ec5-00164112311b}]
\Shell\AutoRun\command - E:\setupSNK.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)

.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = www.yahoomail.com
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 -: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 -: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-03 00:23:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-03  0:25:16
ComboFix-quarantined-files.txt  2008-09-03 05:25:10
Pre-Run: 55,672,000,512 bytes free
Post-Run: 55,760,867,328 bytes free
191 --- E O F --- 2008-08-29 16:56:03
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:39 AM, on 9/3/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoomail.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1220377974437
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 9680 bytes
 
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 09/03/2008 at 00:00 AM
Application Version : 4.20.1046
Core Rules Database Version : 3555
Trace Rules Database Version: 1543
Scan type       : Complete Scan
Total Scan Time : 00:50:08
Memory items scanned      : 494
Memory threats detected   : 0
Registry items scanned    : 5512
Registry threats detected : 0
File items scanned        : 25180
File threats detected     : 46
Adware.Tracking Cookie
 C:\Documents and Settings\Maika\Cookies\maika@indextools[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@specificclick[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@media.adrevolver[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@media.adrevolver[3].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@fastclick[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@realmedia[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@eas.apm.emediate[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@burstnet[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@adserver.adtechus[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@chitika[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@questionmarket[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@dynamic.media.adrevolver[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@data.coremetrics[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@richmedia.yahoo[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@ads.realtechnetwork[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@ads.addynamix[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@adrevolver[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@ads.pointroll[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@tribalfusion[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@www.burstnet[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@yieldmanager[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@precisionclick[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@ads.lucidmedia[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@interclick[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@advertising[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@adopt.specificclick[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@azjmp[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@doubleclick[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@atdmt[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@media6degrees[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@ad.yieldmanager[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@adlegend[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@adserving.contextualmarketplace[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@apmebf[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@mediaplex[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@myroitracking[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@statcounter[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@trafficmp[1].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@www.burstbeacon[2].txt
 C:\Documents and Settings\Victoria\Cookies\victoria@zedo[2].txt
Trojan.Dropper/LWPWER
 C:\DOCUMENTS AND SETTINGS\TAY\LOCAL SETTINGS\TEMP\LWPWER.EXE
Adware.AdRotate/System
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{A034C43B-9B81-4ECD-9C5D-5A084A4D6136}\RP74\A0043635.DLL
Trojan.Dropper/Gen
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{A034C43B-9B81-4ECD-9C5D-5A084A4D6136}\RP74\A0043637.EXE
Trojan.Net-MSV/VPS-Variant
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{A034C43B-9B81-4ECD-9C5D-5A084A4D6136}\RP74\A0043641.DLL
Trojan.Unclassified/GTS
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{A034C43B-9B81-4ECD-9C5D-5A084A4D6136}\RP74\A0043642.DLL
Adware.180solutions/Seekmo/Zango
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{A034C43B-9B81-4ECD-9C5D-5A084A4D6136}\RP79\A0049072.DLL

Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 9-3-2008 8:26 (GMT +1)    Quote: Please help with debug virus adware/spywareAlert an admin about: Please help with debug virus adware/spyware
Hello smile
 
 
Please download Malwarebytes' Anti-Malware:
 
Or here:
 
 to your desktop.
 
Double-click mbam-setup.exe and follow the prompts to install the program.
                     
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch


Malwarebytes' Anti-Malware, then click Finish.
                     
If an update is found, it will download and install the latest version.
                     
Once the program has loaded, select Perform full scan, then click Scan.
                     
When the scan is complete, click OK, then Show Results to view the results.
 
Be sure that everything is checked, and click Remove Selected.
 
When completed, a log will open in Notepad. Please save it to a convenient location.
 
Copy and Paste that log into your next reply, along with fresh combofix log.
 
 
NB: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
 


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

Maika
New Member


Date Joined Sep 2008
Total Posts : 4
 
   Posted 9-3-2008 7:53 (GMT +1)    Quote: Please help with debug virus adware/spywareAlert an admin about: Please help with debug virus adware/spyware
Malwarebytes' Anti-Malware 1.26
Database version: 1103
Windows 5.1.2600 Service Pack 3
9/3/2008 1:24:16 PM
mbam-log-2008-09-03 (13-24-16).txt
Scan type: Full Scan (C:\|)
Objects scanned: 101631
Time elapsed: 1 hour(s), 22 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\System Volume Information\_restore{A034C43B-9B81-4ECD-9C5D-5A084A4D6136}\RP74\A0043634.exe (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{A034C43B-9B81-4ECD-9C5D-5A084A4D6136}\RP74\A0043638.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{A034C43B-9B81-4ECD-9C5D-5A084A4D6136}\RP74\A0043640.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\svchost.PIF (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
ComboFix 08-09-01.04 - Maika 2008-09-03 13:26:23.2 - NTFSx86
Running from: C:\Documents and Settings\Maika\Desktop\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
(((((((((((((((((((((((((   Files Created from 2008-08-03 to 2008-09-03  )))))))))))))))))))))))))))))))
.
2008-09-03 11:53 . 2008-09-03 11:53 <DIR> d-------- C:\WINDOWS\LastGood
2008-09-03 11:36 . 2008-09-03 11:47 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-03 11:36 . 2008-09-03 11:36 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\Malwarebytes
2008-09-03 11:36 . 2008-09-03 11:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-03 11:36 . 2008-09-02 00:16 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-03 11:36 . 2008-09-02 00:16 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-03 00:31 . 2008-09-03 00:32 <DIR> d-------- C:\HJT
2008-09-02 23:01 . 2008-09-02 23:01 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-02 23:01 . 2008-09-02 23:01 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\SUPERAntiSpyware.com
2008-09-02 23:01 . 2008-09-02 23:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-02 23:00 . 2008-09-02 23:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-02 22:53 . 2008-09-02 22:53 <DIR> d-------- C:\Program Files\CCleaner
2008-09-02 21:32 . 2008-04-13 19:12 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-02 20:17 . 2008-09-02 20:17 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-02 19:51 . 2004-08-04 05:00 10,457 -----c--- C:\WINDOWS\system32\dllcache\wmptour.hta
2008-09-02 19:51 . 2004-08-04 05:00 1,771 -----c--- C:\WINDOWS\system32\dllcache\wmptour.css
2008-09-02 19:51 . 2004-08-04 05:00 855 -----c--- C:\WINDOWS\system32\dllcache\wmpocm.inf
2008-09-02 19:51 . 2004-08-04 05:00 420 -----c--- C:\WINDOWS\system32\dllcache\wmploc.js
2008-09-02 19:49 . 2004-08-04 05:00 300,969 -----c--- C:\WINDOWS\system32\dllcache\viz.wmv
2008-09-02 19:48 . 2008-04-13 19:12 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-09-02 19:47 . 2008-04-13 19:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-09-02 19:46 . 2008-04-13 19:12 380,416 --a------ C:\WINDOWS\system32\irprops.cpl
2008-09-02 19:45 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-09-02 19:44 . 2008-04-13 19:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-09-02 12:54 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-02 12:54 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-02 10:42 . 2008-09-02 10:42 <DIR> d--h----- C:\WINDOWS\PIF
2008-09-02 10:28 . 2008-09-02 10:28 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-09-02 10:13 . 2008-09-03 13:26 <DIR> d-------- C:\QUARANTINE
2008-09-02 10:10 . 2008-09-02 10:10 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-09-02 10:10 . 2008-09-02 10:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-02 10:10 . 2006-11-17 03:06 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2008-09-02 10:10 . 2006-11-17 03:06 280 --a------ C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-09-02 10:09 . 2008-09-02 10:10 <DIR> d-------- C:\Program Files\McAfee
2008-09-02 10:09 . 2008-09-02 10:09 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-09-02 10:09 . 2006-11-30 08:50 168,776 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-09-02 10:09 . 2006-11-30 08:50 72,264 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-09-02 10:09 . 2006-11-30 08:50 64,360 --a------ C:\WINDOWS\system32\drivers\mfeapfk.sys
2008-09-02 10:09 . 2006-11-30 08:50 52,136 --a------ C:\WINDOWS\system32\drivers\mfetdik.sys
2008-09-02 10:09 . 2006-11-30 08:50 34,152 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-09-02 06:21 . 2008-09-02 06:23 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-09-02 06:21 . 2008-09-02 06:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-31 19:16 . 2008-08-31 22:17 <DIR> d-------- C:\Documents and Settings\Victoria\Application Data\COMCASTTOOLBAR
2008-08-29 00:50 . 2008-08-29 00:55 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-08-29 00:50 . 2008-08-29 00:50 <DIR> d-------- C:\Program Files\ComcastToolbar
2008-08-29 00:50 . 2008-09-03 13:01 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\ComcastToolbar
2008-08-29 00:45 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-29 00:41 . 2008-08-29 00:41 <DIR> d-------- C:\Program Files\Viewpoint
2008-08-29 00:41 . 2008-08-29 00:41 <DIR> d-------- C:\Program Files\SigmaTel
2008-08-29 00:41 . 2008-08-29 00:41 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\Runaware
2008-08-29 00:36 . 2008-08-29 00:36 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-08-05 12:16 . 2008-08-05 12:18 <DIR> d-------- C:\WINDOWS\privacy_danger(2)
2008-08-05 11:57 . 2008-08-05 11:57 <DIR> d-------- C:\WINDOWS\McAfee.com
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-03 16:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-03 16:37 --------- d-----w C:\Program Files\Microsoft Works
2008-09-02 15:56 --------- d-----w C:\Program Files\SuperStar
2008-08-29 05:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-17 19:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-11 18:26 --------- d-----w C:\Documents and Settings\Victoria\Application Data\dvdcss
2008-08-08 05:56 --------- d-----w C:\Program Files\PokerStars
2008-08-03 21:38 --------- d-----w C:\Documents and Settings\Maika\Application Data\dvdcss
2008-07-26 04:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-07-20 22:55 --------- d-----w C:\Program Files\INVENT
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es(2)(3).dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-06 17:11 --------- d-----w C:\Program Files\Common Files\xing shared
2008-07-06 17:11 --------- d-----w C:\Program Files\Common Files\Real
2008-07-06 17:10 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-06 17:10 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-07-06 17:10 --------- d-----w C:\Program Files\Real
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet(3)(2).dll
2008-06-23 16:57 267,776 ----a-w C:\WINDOWS\system32\iertutil(2)(3).dll
2008-06-23 16:57 105,984 ----a-w C:\WINDOWS\system32\url(3)(2).dll
2008-06-23 16:57 1,159,680 ----a-w C:\WINDOWS\system32\urlmon(3)(2).dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
(((((((((((((((((((((((((((((   snapshot@2008-09-03_ 0.24.45.39   )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-10-27 20:07:36 17,891,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\EXCEL.EXE
+ 2006-10-27 20:04:08 497,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\MORPH9.DLL
+ 2006-10-27 20:04:10 9,581,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\MSPUB.EXE
+ 2006-10-27 01:42:36 8,423,224 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\OARTCONV.DLL
+ 2006-09-15 21:25:18 3,611,416 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT
+ 2006-10-27 20:04:06 465,200 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\POWERPNT.EXE
+ 2006-10-27 20:04:06 7,980,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\PPCORE.DLL
+ 2006-10-27 01:09:36 136,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\PRTF9.DLL
+ 2006-10-27 20:04:06 624,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\PTXT9.DLL
+ 2006-10-27 01:09:44 590,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\PUBCONV.DLL
+ 2006-10-27 20:23:04 347,432 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\WINWORD.EXE
+ 2006-10-27 20:11:38 4,235,560 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\WRD12CNV.DLL
+ 2006-10-27 20:11:36 21,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\WRD12EXE.EXE
+ 2006-10-27 20:23:08 17,483,560 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\WWLIB.DLL
+ 2006-10-27 02:13:08 14,674,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\XL12CNV.EXE
+ 2006-10-27 02:17:08 11,072 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0[/u]0002119410000000000000000F01FEC\12.0.4518\XLCALL32.DLL
+ 2003-07-15 08:13:58 166,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\ACCWIZ.DLL
+ 2003-07-15 03:43:20 87,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\ADDRPARS.DLL
+ 2003-07-15 03:57:34 38,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\AUTHZAX.DLL
+ 2003-07-15 03:53:06 94,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\AW.DLL
+ 2003-07-15 03:53:24 60,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\BLNMGR.DLL
+ 2003-07-15 03:53:22 46,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\BLNMGRPS.DLL
+ 2003-07-15 08:14:28 350,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\CDLMSO.DLL
+ 2003-07-15 08:18:12 47,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\DFUICOM.EXE
+ 2003-07-25 23:57:20 75,832 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\DLGSETP.DLL
+ 2003-07-15 03:56:54 14,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\DSITF.DLL
+ 2003-07-15 03:57:14 98,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\DSSM.EXE
+ 2003-07-31 20:19:52 131,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\ENVELOPE.DLL
+ 2003-08-13 07:34:38 10,073,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\EXCEL.EXE
+ 2003-07-15 03:41:44 13,368 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FINDER.EXE
+ 2002-10-07 14:49:36 192,573 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FORM.DLL
+ 2003-07-24 04:01:40 1,949,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPCUTL.DLL
+ 2003-07-15 04:36:14 186,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPDTC.DLL
+ 2003-07-26 00:00:16 1,157,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPSRVUTL.DLL
+ 2003-07-26 00:14:50 799,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPWEC.DLL
+ 2003-07-15 04:11:42 2,139,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\GRAPH.EXE
+ 2003-07-15 03:57:44 87,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\IEAWSDC.DLL
+ 2003-07-24 03:32:32 121,400 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\IMPMAIL.DLL
+ 2003-08-01 20:07:36 4,815,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\INFOPATH.EXE
+ 2003-07-15 03:45:14 58,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\INLAUNCH.DLL
+ 2003-06-18 22:31:44 758,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIGRAPH.DLL
+ 2003-06-18 22:31:10 252,928 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIINK.DLL
+ 2003-06-18 22:31:48 17,920 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIMON.DLL
+ 2003-06-18 22:31:48 18,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIPPR.DLL
+ 2003-06-18 22:31:46 35,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIUI.DLL
+ 2003-06-18 22:31:34 443,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIVWCTL.DLL
+ 2003-07-15 03:46:08 176,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MIMEDIR.DLL
+ 2003-07-15 04:01:44 445,496 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MODHELP.DLL
+ 2003-08-15 05:54:08 6,627,392 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSACCESS.EXE
+ 2003-07-15 08:13:58 130,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSAEXP30.DLL
+ 2003-07-15 03:56:14 40,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSE7.EXE
+ 2003-07-15 03:51:44 87,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSENCODE.DLL
+ 2003-07-15 08:14:00 139,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSJSPP40.DLL
+ 2003-07-15 03:52:52 17,464 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSMH.DLL
+ 2003-08-08 05:23:16 12,172,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSO.DLL
+ 2003-07-15 03:57:16 120,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOAUTH.DLL
+ 2003-07-15 08:14:18 106,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOCF.DLL
+ 2003-07-24 03:35:26 127,032 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOCFU.DLL
+ 2003-07-15 03:52:52 27,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSODCW.DLL
+ 2003-07-15 03:52:56 55,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOHTMED.EXE
+ 2003-07-15 03:56:16 54,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOMSE.DLL
+ 2003-07-15 03:52:54 28,224 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOSTYLE.DLL
+ 2003-07-15 03:53:00 55,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOSVABW.DLL
+ 2003-07-15 03:53:20 39,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOSVFBR.DLL
+ 2003-07-15 03:46:16 42,040 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
+ 2003-07-15 03:45:12 55,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
+ 2003-07-15 03:45:12 39,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
+ 2003-06-18 22:31:24 1,033,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPCORE.DLL
+ 2003-06-18 22:31:54 788,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPFILT.DLL
+ 2003-06-18 22:31:50 16,384 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
+ 2003-06-19 21:05:52 128,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPSCAN.EXE
+ 2003-07-28 17:24:40 5,677,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPUB.EXE
+ 2003-06-19 21:05:50 364,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPVIEW.EXE
+ 2003-07-15 04:02:42 637,496 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSQRY32.EXE
+ 2003-07-15 03:52:58 41,528 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
+ 2003-07-15 04:02:14 627,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSTORDB.EXE
+ 2003-07-15 03:56:24 124,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSTORE.EXE
+ 2003-07-24 03:40:00 482,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSTORES.DLL
+ 2003-07-15 04:00:54 145,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSWEBCAP.DLL
+ 2003-07-15 03:57:10 56,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\NAME.DLL
+ 2003-07-15 03:56:52 13,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
+ 2003-06-18 22:31:58 6,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OCRPS.DLL
+ 2003-07-15 08:14:26 283,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OIS.EXE
+ 2003-07-15 08:14:26 828,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OISAPP.DLL
+ 2003-07-15 08:14:26 27,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
+ 2003-07-15 08:14:26 242,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OISGRAPH.DLL
+ 2003-07-15 04:05:24 1,054,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OMFC.DLL
+ 2003-07-15 04:05:24 1,054,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OMFC.DLL_0002
+ 2003-07-15 03:53:08 95,792 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OSA.EXE
+ 2003-07-15 03:41:56 24,640 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLACCT.DLL
+ 2003-07-15 03:44:34 102,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLCTL.DLL
+ 2003-07-07 18:36:00 2,058,343 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DAT
+ 2003-07-08 16:48:00 115,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DLL
+ 2003-08-10 04:06:42 7,522,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLLIB.DLL
+ 2003-07-15 03:44:32 88,128 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLMIME.DLL
+ 2003-07-15 03:45:18 196,152 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLOOK.EXE
+ 2003-07-15 03:43:48 139,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLPH.DLL
+ 2003-07-15 03:43:18 64,056 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLRPC.DLL
+ 2003-07-15 03:43:16 49,208 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLWAB.DLL
+ 2003-08-04 18:19:34 7,330,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OWC10.DLL
+ 2003-08-01 20:09:04 8,086,072 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OWC11.DLL
+ 2003-07-30 17:40:40 6,133,312 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\POWERPNT.EXE
+ 2003-07-15 08:18:54 430,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PP4X322.DLL
+ 2003-07-15 08:18:44 93,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
+ 2003-07-31 20:21:08 1,782,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PPTVIEW.EXE
+ 2003-07-15 03:40:26 130,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PRTF9.DLL
+ 2002-10-07 15:11:00 167,997 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PSOM.DLL
+ 2003-07-15 03:51:12 604,728 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PTXT9.DLL
+ 2003-07-15 03:50:26 551,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PUBCONV.DLL
+ 2003-07-15 03:40:16 51,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PUBTRAP.DLL
+ 2003-07-15 03:42:26 37,432 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\RECALL.DLL
+ 2003-05-09 02:54:00 77,824 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
+ 2003-07-15 03:57:08 40,512 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
+ 2002-10-07 14:49:42 81,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\REVERSE.DLL
+ 2003-07-15 03:43:30 74,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\RM.DLL
+ 2003-07-21 16:46:38 390,712 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\RTFHTML.DLL
+ 2003-07-15 03:57:18 349,248 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SELFCERT.EXE
+ 2003-07-15 03:44:16 66,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SENDTO.DLL
+ 2003-07-15 03:57:08 58,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
+ 2003-08-06 18:31:22 362,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SETLANG.EXE
+ 2003-08-06 18:26:18 445,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SOA.DLL
+ 2003-08-03 15:52:32 2,808,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\STSLIST.DLL
+ 2002-10-07 14:53:04 106,561 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\THOCRAPI.DLL
+ 2003-07-15 04:00:22 99,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TRANSMGR.DLL
+ 2002-10-07 14:50:44 241,729 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TWCUTCHR.DLL
+ 2002-10-07 14:51:04 180,289 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TWCUTLIN.DLL
+ 2002-10-07 14:51:14 147,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TWLAY32.DLL
+ 2002-10-07 14:51:20 102,467 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TWORIENT.DLL
+ 2002-10-07 14:50:04 118,847 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TWRECE.DLL
+ 2002-10-07 14:49:56 81,983 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TWRECS.DLL
+ 2002-10-07 14:51:44 221,252 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TWSTRUCT.DLL
+ 2003-07-15 03:57:40 59,960 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\UNBIND.EXE
+ 2003-08-06 18:24:20 12,037,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\WINWORD.EXE
+ 2002-10-07 15:03:34 1,794,113 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\XIMAGE3B.DLL
+ 2003-04-30 16:52:32 1,581,120 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\XPAGE3C.DLL
+ 2003-01-17 19:03:34 59,466 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\XSCAN32.DAT
- 2008-06-30 23:52:34 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-09-03 16:43:43 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-06-30 23:52:34 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-09-03 16:43:43 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-06-30 23:52:34 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-09-03 16:43:43 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-06-30 23:52:34 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-09-03 16:43:43 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-06-30 23:52:34 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-09-03 16:43:43 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-06-30 23:52:35 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-09-03 16:43:43 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-06-30 23:52:35 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-09-03 16:43:43 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-06-30 23:52:35 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-09-03 16:43:43 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-06-30 23:52:34 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-09-03 16:43:43 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-06-30 23:52:34 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-09-03 16:43:43 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-06-30 23:52:35 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-09-03 16:43:44 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-06-30 23:52:34 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-09-03 16:43:43 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-06-30 23:52:34 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-09-03 16:43:42 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-06-30 23:30:37 1,165,584 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-09-03 16:45:12 1,165,584 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
- 2008-06-30 23:30:37 20,240 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-09-03 16:45:12 20,240 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-06-30 23:30:37 217,864 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2008-09-03 16:45:12 217,864 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
- 2008-06-30 23:30:37 18,704 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-09-03 16:45:13 18,704 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-06-30 23:30:37 35,088 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-09-03 16:45:13 35,088 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-06-30 23:30:37 845,584 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-09-03 16:45:12 845,584 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
- 2008-06-30 23:30:37 922,384 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-09-03 16:45:12 922,384 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
- 2008-06-30 23:30:37 272,648 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-09-03 16:45:12 272,648 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
- 2008-06-30 23:30:37 888,080 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-09-03 16:45:13 888,080 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-06-30 23:30:37 1,172,240 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-09-03 16:45:12 1,172,240 ----a-r C:\WINDOWS\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-07-19 03:10:48 94,920 ------w C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\cdm.dll
+ 2008-07-19 03:09:44 563,912 ------w C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuapi.dll
+ 2008-07-19 03:10:42 53,448 ------w C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuauclt.exe
+ 2008-07-19 03:09:42 1,811,656 ------w C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuaueng.dll
+ 2008-07-19 03:09:46 325,832 ------w C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wucltui.dll
+ 2008-07-19 03:10:20 36,552 ------w C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wups.dll
+ 2008-07-19 03:10:40 45,768 ------w C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wups2.dll
+ 2008-07-19 03:09:44 205,000 ------w C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuweb.dll
- 2006-10-26 19:10:08 1,190,688 ----a-w C:\WINDOWS\system32\FM20.DLL
+ 2007-06-06 15:53:34 1,195,888 ----a-w C:\WINDOWS\system32\FM20.DLL
- 2003-06-18 22:31:48 17,920 ----a-w C:\WINDOWS\system32\mdimon.dll
+ 2007-04-09 18:23:54 28,040 ----a-w C:\WINDOWS\system32\mdimon.dll
- 2003-06-18 22:31:44 758,784 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2007-04-09 18:24:04 758,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
- 2003-06-18 22:31:46 35,328 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2007-04-09 18:23:58 46,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
- 2003-06-18 22:31:44 758,784 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
+ 2007-04-09 18:24:04 758,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
- 2003-06-18 22:31:46 35,328 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
+ 2007-04-09 18:23:58 46,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
- 2003-06-18 22:31:48 18,944 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2007-04-09 18:23:54 28,552 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
.
-- Snapshot reset to current date --
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-07-28 05:46 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 223984]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-08-19 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 223984]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 176128]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-07-06 185896]
"YMailAdvisor"="C:\Program Files\Yahoo!\Common\YMailAdvisor.exe" [2008-06-05 125208]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 C:\WINDOWS\system32\bthprops.cpl]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 1724416]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-04-05 11:26 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 GoToAssist;GoToAssist;C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe Start=service [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4eafb541-f1cd-11dc-9e5b-806d6172696f}]
\Shell\AutoRun\command - F:\launcher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77230a70-205f-11dd-9ec5-00164112311b}]
\Shell\AutoRun\command - E:\setupSNK.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = www.yahoomail.com
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 -: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 -: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-03 13:29:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...

**************************************************************************
.
Completion time: 2008-09-03 13:31:36
ComboFix-quarantined-files.txt  2008-09-03 18:30:31
ComboFix2.txt  2008-09-03 05:25:17
Pre-Run: 54,789,193,728 bytes free
Post-Run: 54,812,237,824 bytes free
381 --- E O F --- 2008-09-03 16:45:19
Thanks for responding so quickly! :-) 


Maika

Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 9-6-2008 3:12 (GMT +1)    Quote: Please help with debug virus adware/spywareAlert an admin about: Please help with debug virus adware/spyware
 and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
 and save it to your desktop.

When you have done this, please boot into Safe Mode (Tap F8 during startup).

Open the extracted folder  - C:\ SDFix  and doubleclick on RunThis.bat to start the script.

Type Y to begin the script. It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot. When you hit any key, your computer will reboot. Your system will take longer that normal to restart as the fixtool will be running and removing files.

When your desktop loads, the utility will complete the removal and display Finished. Press any key again to end the script and load your desktop icons.
 
 
Open the SDFix folder on your desktop and copy and paste the contents of Report.txt, along with new combofix log


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

Maika
New Member


Date Joined Sep 2008
Total Posts : 4
 
   Posted 9-6-2008 9:47 (GMT +1)    Quote: Please help with debug virus adware/spywareAlert an admin about: Please help with debug virus adware/spyware
hello :-)

[b]SDFix: Version 1.221 [/b]
Run by Maika on Sat 09/06/2008 at 03:25 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:

Restoring Default Security Values
Restoring Default Hosts File
Rebooting

[b]Checking Files [/b]:
No Trojan Files Found





Removing Temp Files
[b]ADS Check [/b]:
 

                                 [b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-06 15:31:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00164112311b]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00164112311b]
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

[b]Remaining Services [/b]:



Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"="C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe:*:Enabled:McAfee Framework Service"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[b]Remaining Files [/b]:


[b]Files with Hidden Attributes [/b]:
Sun 22 Jun 2008     1,686,528 ...H. --- "C:\Documents and Settings\Maika\Desktop\~WRL0390.tmp"
Sat 21 Jun 2008     1,622,528 ...H. --- "C:\Documents and Settings\Maika\Desktop\~WRL2065.tmp"
Wed 13 Aug 2008       209,408 A..H. --- "C:\Documents and Settings\All Users\Documents\Final\~WRL0988.tmp"
Wed 13 Aug 2008       229,376 A..H. --- "C:\Documents and Settings\All Users\Documents\Final\~WRL1720.tmp"
Wed 13 Aug 2008       229,376 A..H. --- "C:\Documents and Settings\All Users\Documents\Final\~WRL2578.tmp"
Thu 12 Jun 2008       415,232 ...H. --- "C:\Documents and Settings\Maika\Application Data\Microsoft\Word\~WRL1826.tmp"
Tue 11 Dec 2007        90,624 A..H. --- "C:\Documents and Settings\Maika\Desktop\Program Files\Trimester 1\Spinal Anatomy\~WRL0438.tmp"
Tue 11 Dec 2007        98,304 A..H. --- "C:\Documents and Settings\Maika\Desktop\Program Files\Trimester 1\Spinal Anatomy\~WRL1625.tmp"
Tue 11 Dec 2007        89,600 A..H. --- "C:\Documents and Settings\Maika\Desktop\Program Files\Trimester 1\Spinal Anatomy\~WRL3782.tmp"
Tue 11 Dec 2007        90,624 A..H. --- "C:\Documents and Settings\Maika\Desktop\Tay's Backup SD\Program Files\Trimester 1\Spinal Anatomy\~WRL0438.tmp"
Tue 11 Dec 2007        98,304 A..H. --- "C:\Documents and Settings\Maika\Desktop\Tay's Backup SD\Program Files\Trimester 1\Spinal Anatomy\~WRL1625.tmp"
Tue 11 Dec 2007        89,600 A..H. --- "C:\Documents and Settings\Maika\Desktop\Tay's Backup SD\Program Files\Trimester 1\Spinal Anatomy\~WRL3782.tmp"
[b]Finished![/b]
ComboFix 08-09-05.02 - Maika 2008-09-06 15:39:19.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1009 [GMT -5:00]
Running from: C:\Documents and Settings\Maika\Desktop\ComboFix.exe
 * Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Maika\Cookies\maika@ad.yieldmanager[3].txt
.
(((((((((((((((((((((((((   Files Created from 2008-08-06 to 2008-09-06  )))))))))))))))))))))))))))))))
.
2008-09-06 15:24 . 2008-09-06 15:24 578,560 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
2008-09-06 15:21 . 2008-09-06 15:21 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-06 15:14 . 2008-09-06 15:33 <DIR> d-------- C:\SDFix
2008-09-03 11:36 . 2008-09-03 11:47 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-03 11:36 . 2008-09-03 11:36 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\Malwarebytes
2008-09-03 11:36 . 2008-09-03 11:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-03 11:36 . 2008-09-02 00:16 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-03 11:36 . 2008-09-02 00:16 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-03 00:31 . 2008-09-03 00:32 <DIR> d-------- C:\HJT
2008-09-02 23:01 . 2008-09-04 22:17 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-02 23:01 . 2008-09-02 23:01 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\SUPERAntiSpyware.com
2008-09-02 23:01 . 2008-09-02 23:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-02 23:00 . 2008-09-02 23:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-02 22:53 . 2008-09-02 22:53 <DIR> d-------- C:\Program Files\CCleaner
2008-09-02 21:32 . 2008-04-13 19:12 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-02 20:22 . 2008-09-02 20:22 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-02 20:17 . 2008-09-02 20:17 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-02 19:51 . 2004-08-04 05:00 10,457 -----c--- C:\WINDOWS\system32\dllcache\wmptour.hta
2008-09-02 19:51 . 2004-08-04 05:00 1,771 -----c--- C:\WINDOWS\system32\dllcache\wmptour.css
2008-09-02 19:51 . 2004-08-04 05:00 855 -----c--- C:\WINDOWS\system32\dllcache\wmpocm.inf
2008-09-02 19:51 . 2004-08-04 05:00 420 -----c--- C:\WINDOWS\system32\dllcache\wmploc.js
2008-09-02 19:49 . 2004-08-04 05:00 300,969 -----c--- C:\WINDOWS\system32\dllcache\viz.wmv
2008-09-02 19:48 . 2008-04-13 19:12 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-09-02 19:47 . 2008-04-13 19:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-09-02 19:46 . 2008-04-13 19:12 380,416 --a------ C:\WINDOWS\system32\irprops.cpl
2008-09-02 19:45 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-09-02 19:44 . 2008-04-13 19:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-09-02 12:54 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-02 12:54 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-02 10:42 . 2008-09-02 10:42 <DIR> d--h----- C:\WINDOWS\PIF
2008-09-02 10:28 . 2008-09-02 10:28 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-09-02 10:13 . 2008-09-06 15:39 <DIR> d-------- C:\QUARANTINE
2008-09-02 10:10 . 2008-09-02 10:10 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-09-02 10:10 . 2008-09-02 10:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-02 10:10 . 2006-11-17 03:06 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2008-09-02 10:10 . 2006-11-17 03:06 280 --a------ C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-09-02 10:09 . 2008-09-02 10:10 <DIR> d-------- C:\Program Files\McAfee
2008-09-02 10:09 . 2008-09-02 10:09 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-09-02 10:09 . 2006-11-30 08:50 168,776 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-09-02 10:09 . 2006-11-30 08:50 72,264 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-09-02 10:09 . 2006-11-30 08:50 64,360 --a------ C:\WINDOWS\system32\drivers\mfeapfk.sys
2008-09-02 10:09 . 2006-11-30 08:50 52,136 --a------ C:\WINDOWS\system32\drivers\mfetdik.sys
2008-09-02 10:09 . 2006-11-30 08:50 34,152 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-09-02 06:21 . 2008-09-02 06:23 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-09-02 06:21 . 2008-09-02 06:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-31 19:16 . 2008-08-31 22:17 <DIR> d-------- C:\Documents and Settings\Victoria\Application Data\COMCASTTOOLBAR
2008-08-29 00:50 . 2008-08-29 00:55 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-08-29 00:50 . 2008-08-29 00:50 <DIR> d-------- C:\Program Files\ComcastToolbar
2008-08-29 00:50 . 2008-09-06 15:08 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\ComcastToolbar
2008-08-29 00:45 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-29 00:41 . 2008-08-29 00:41 <DIR> d-------- C:\Program Files\Viewpoint
2008-08-29 00:41 . 2008-08-29 00:41 <DIR> d-------- C:\Program Files\SigmaTel
2008-08-29 00:41 . 2008-08-29 00:41 <DIR> d-------- C:\Documents and Settings\Maika\Application Data\Runaware
2008-08-29 00:36 . 2008-08-29 00:36 <DIR> d-------- C:\Program Files\MSXML 4.0
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-05 16:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-03 16:37 --------- d-----w C:\Program Files\Microsoft Works
2008-09-02 15:56 --------- d-----w C:\Program Files\SuperStar
2008-08-29 05:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-17 19:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-11 18:26 --------- d-----w C:\Documents and Settings\Victoria\Application Data\dvdcss
2008-08-08 05:56 --------- d-----w C:\Program Files\PokerStars
2008-08-03 21:38 --------- d-----w C:\Documents and Settings\Maika\Application Data\dvdcss
2008-07-26 04:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-07-20 22:55 --------- d-----w C:\Program Files\INVENT
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es(2)(3).dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-06 17:11 --------- d-----w C:\Program Files\Common Files\xing shared
2008-07-06 17:11 --------- d-----w C:\Program Files\Common Files\Real
2008-07-06 17:10 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-06 17:10 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-07-06 17:10 --------- d-----w C:\Program Files\Real
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet(3)(2).dll
2008-06-23 16:57 267,776 ----a-w C:\WINDOWS\system32\iertutil(2)(3).dll
2008-06-23 16:57 105,984 ----a-w C:\WINDOWS\system32\url(3)(2).dll
2008-06-23 16:57 1,159,680 ----a-w C:\WINDOWS\system32\urlmon(3)(2).dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
(((((((((((((((((((((((((((((   snapshot_2008-09-03_13.30.07.68   )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-07 09:07:23 135,168 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\cscript.exe
+ 2008-05-09 10:45:15 512,000 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\jscript.dll
+ 2008-05-09 10:45:16 180,224 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\scrobj.dll
+ 2008-05-09 10:45:16 172,032 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\scrrun.dll
+ 2008-05-09 10:45:16 430,080 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\vbscript.dll
+ 2008-05-08 11:24:44 155,648 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wscript.exe
+ 2008-05-09 10:45:17 90,112 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wshext.dll
+ 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951978\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951978\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 ----a-w&nbs