SMOKIN420311
2008-07-23, 15:35
ComboFix 08-07-22.4 - sedin 2008-07-23 8:17:00.1 - NTFSx86
Running from: C:\Documents and Settings\sedin\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ahxeckig.ini
C:\WINDOWS\system32\dspjtbwb.ini
C:\WINDOWS\system32\eduqkckf.ini
C:\WINDOWS\system32\fqtcbpxd.ini
C:\WINDOWS\system32\fxuumawl.dll
C:\WINDOWS\system32\klmlRqru.ini
C:\WINDOWS\system32\klmlRqru.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mktfxncl.ini
C:\WINDOWS\system32\nrtmmywa.ini
C:\WINDOWS\system32\OruENXbc.ini
C:\WINDOWS\system32\OruENXbc.ini2
C:\WINDOWS\system32\qvefhw.dll
C:\WINDOWS\system32\uckpicde.dll
C:\WINDOWS\system32\uomivlup.dll
C:\WINDOWS\system32\wbcbpsdo.ini
C:\WINDOWS\system32\wfyhlu.dll
C:\WINDOWS\system32\wmhnolqi.ini
C:\WINDOWS\system32\xmxlucub.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))
.
2008-07-21 11:48 . 2008-07-21 12:28 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\Paltalk
2008-07-21 11:47 . 2008-07-21 11:47 <DIR> d-------- C:\WINDOWS\PaltalkScene
2008-07-21 11:47 . 2008-07-21 12:28 <DIR> d-------- C:\Program Files\Paltalk Messenger
2008-07-18 14:52 . 2008-07-18 14:52 <DIR> d-------- C:\Program Files\GameTap
2008-07-18 14:52 . 2008-07-18 15:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GameTap
2008-07-16 15:59 . 2008-07-16 15:59 <DIR> d-------- C:\VundoFix Backups
2008-07-16 15:32 . 2008-07-16 15:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-16 13:53 . 2008-07-16 13:54 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-16 13:53 . 2008-07-16 14:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-16 11:03 . 2008-07-16 11:03 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-16 11:03 . 2008-07-16 11:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-16 08:30 . 2008-07-16 08:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-16 08:29 . 2008-07-23 08:11 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-16 08:29 . 2008-07-23 08:12 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\SUPERAntiSpyware.com
2008-07-16 08:21 . 2008-07-16 08:21 <DIR> d-------- C:\Documents and Settings\downloads\SUPERAntiSpyware Professional v4.15.1000 + Cracks [Lifetime Subscription]
2008-07-16 08:15 . 2008-07-23 08:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-15 14:45 . 2008-07-15 14:45 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-07-15 14:45 . 2008-07-15 14:45 <DIR> d-------- C:\WINDOWS\system32\en
2008-07-15 14:45 . 2008-07-15 14:45 <DIR> d-------- C:\WINDOWS\system32\bits
2008-07-15 14:45 . 2008-07-15 14:45 <DIR> d-------- C:\WINDOWS\l2schemas
2008-07-15 14:41 . 2008-07-15 14:46 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-07-15 14:28 . 2008-07-15 14:28 <DIR> d-------- C:\Program Files\Codec Pack - All In 1
2008-07-15 14:28 . 2008-07-15 14:26 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-07-15 12:40 . 2008-07-15 12:40 <DIR> d-------- C:\Documents and Settings\testuser\Application Data\TeamViewer
2008-07-15 12:40 . 2008-07-15 12:40 <DIR> d-------- C:\Documents and Settings\testuser\Application Data\SiteAdvisor
2008-07-15 12:37 . 2008-07-15 12:38 <DIR> d-------- C:\Documents and Settings\testuser
2008-07-15 08:59 . 2008-07-15 08:59 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\TeamViewer
2008-07-15 08:11 . 2008-07-15 08:11 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\TeamViewer
2008-07-15 08:11 . 2008-07-15 08:11 <DIR> d-------- C:\Program Files\TeamViewer3
2008-07-15 08:11 . 2008-07-15 08:13 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\TeamViewer
2008-07-15 08:10 . 2008-07-15 08:10 <DIR> d-------- C:\Documents and Settings\sedin\temp
2008-07-14 15:44 . 2008-07-14 15:44 <DIR> d-------- C:\Program Files\GameTap Web Player
2008-07-14 15:44 . 2008-07-14 15:44 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\InstallShield
2008-07-14 15:36 . 2008-07-14 15:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GameTap Web Player
2008-07-14 08:14 . 2008-07-14 08:14 <DIR> d-------- C:\Documents and Settings\collector\Application Data\SiteAdvisor
2008-07-14 08:11 . 2008-07-14 08:12 <DIR> d-------- C:\Documents and Settings\collector
2008-07-10 14:24 . 2008-07-10 14:24 <DIR> d-------- C:\Documents and Settings\downloads\Microsoft .NET Framework 3.5
2008-07-10 14:07 . 2008-07-10 14:11 <DIR> d-------- C:\Documents and Settings\downloads\microsoft .netframework all version
2008-07-10 12:32 . 2008-07-10 12:32 <DIR> d-------- C:\WINDOWS\WinRAR
2008-07-10 11:54 . 2008-07-16 08:21 <DIR> d-------- C:\Documents and Settings\downloads
2008-07-10 11:48 . 2008-07-10 11:48 <DIR> d-------- C:\Program Files\uTorrent
2008-07-10 11:48 . 2008-07-16 08:24 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\uTorrent
2008-07-07 12:33 . 2008-07-22 08:53 <DIR> d-------- C:\Program Files\Winamp
2008-07-07 12:33 . 2008-07-22 08:52 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\Winamp
2008-07-07 11:36 . 2008-04-13 15:17 83,072 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-07-07 11:36 . 2008-04-13 14:45 56,576 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-07-07 11:36 . 2008-04-13 14:45 52,864 --a------ C:\WINDOWS\system32\drivers\dmusic.sys
2008-07-07 11:36 . 2008-04-13 14:45 6,272 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-07-07 11:35 . 2008-04-13 14:45 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-07-07 11:35 . 2008-04-13 12:39 142,592 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-07-07 11:35 . 2008-04-13 15:15 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-07-07 11:35 . 2008-04-13 14:39 7,552 --a------ C:\WINDOWS\system32\drivers\mskssrv.sys
2008-07-07 11:35 . 2008-04-13 14:39 5,376 --a------ C:\WINDOWS\system32\drivers\mspclock.sys
2008-07-07 11:35 . 2008-04-13 14:39 4,992 --a------ C:\WINDOWS\system32\drivers\mspqm.sys
2008-07-07 11:35 . 2008-04-13 14:45 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2008-07-07 11:33 . 2007-05-10 10:23 4,952,064 --a------ C:\WINDOWS\system32\stacgui.cpl
2008-07-07 11:33 . 2007-04-10 17:02 1,601,536 --a------ C:\WINDOWS\system32\stlang.dll
2008-07-07 11:33 . 2007-05-10 10:22 405,504 --a------ C:\WINDOWS\stsystra.exe
2008-07-07 11:31 . 2008-04-13 20:12 129,536 --a------ C:\WINDOWS\system32\ksproxy.ax
2008-07-07 11:31 . 2008-04-13 14:45 60,160 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-07-07 11:31 . 2008-04-13 20:11 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-07-07 11:29 . 2008-07-07 11:29 <DIR> d-------- C:\Program Files\SigmaTel
2008-07-07 11:29 . 2007-05-10 10:24 1,222,840 --a------ C:\WINDOWS\system32\drivers\sthda.sys
2008-07-07 11:29 . 2007-05-10 10:23 270,336 --a------ C:\WINDOWS\system32\stacapi.dll
2008-07-07 11:29 . 2007-08-21 09:58 146,944 --a------ C:\WINDOWS\system32\st325602.dll
2008-07-07 11:28 . 2008-07-07 11:28 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-07-07 11:22 . 2008-07-07 11:22 <DIR> d-------- C:\WINDOWS\system32\Dell
2008-07-07 11:22 . 2008-07-07 11:22 <DIR> d-------- C:\Program Files\Dell
2008-07-07 10:58 . 2008-07-14 08:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CollectionsManager
2008-07-07 10:51 . 2008-07-07 11:08 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\SiteAdvisor
2008-07-07 10:49 . 2008-07-07 10:49 <DIR> d-------- C:\Program Files\Microsoft Windows Small Business Server
2008-07-07 10:46 . 2008-07-22 08:00 <DIR> d-------- C:\Documents and Settings\sedin
2008-06-26 13:37 . 2008-06-26 13:37 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-06-26 13:23 . 2008-07-23 08:21 3,434 --a------ C:\WINDOWS\system32\Config.MPF
2008-06-26 13:08 . 2008-06-26 15:05 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-06-26 13:08 . 2008-06-26 13:33 <DIR> d-------- C:\Documents and Settings\user\Application Data\SiteAdvisor
2008-06-26 13:08 . 2008-06-26 13:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-06-26 13:06 . 2006-05-15 16:24 86,880 --a------ C:\WINDOWS\system32\drivers\WscNetDr.sys
2008-06-26 13:03 . 2005-04-20 19:22 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-06-26 13:03 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-06-26 12:58 . 2006-10-26 09:56 168,392 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-06-26 12:58 . 2007-07-13 06:20 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-06-26 12:58 . 2006-10-26 09:56 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-06-26 12:58 . 2006-10-26 09:56 35,048 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-06-26 12:58 . 2006-10-26 09:56 34,120 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-06-26 12:58 . 2006-10-26 09:56 31,944 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-06-26 12:54 . 2008-06-26 12:56 <DIR> d-------- C:\Program Files\McAfee.com
2008-06-26 12:52 . 2008-06-26 13:10 <DIR> d-------- C:\Program Files\McAfee
2008-06-26 12:52 . 2008-06-26 16:28 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-06-26 12:51 . 2008-06-26 13:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-26 12:05 . 2008-06-26 12:05 <DIR> d-------- C:\Program Files\PowerISO
2008-06-26 11:03 . 2008-06-26 11:04 <DIR> d-------- C:\Documents and Settings\user\Application Data\Media Player Classic
2008-06-24 15:42 . 2008-04-13 14:45 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-24 15:42 . 2008-04-13 20:11 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-06-24 15:42 . 2008-04-13 14:39 14,592 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-23 10:46 . 2008-06-23 10:55 247 --a------ C:\WINDOWS\lexstat.ini
2008-06-23 10:44 . 2008-06-23 10:44 <DIR> d-------- C:\Program Files\Lexmark Z700-P700 Series
2008-06-23 10:44 . 2008-06-23 10:44 <DIR> d-------- C:\Documents and Settings\user\WINDOWS
2008-06-23 10:43 . 2008-06-23 10:43 <DIR> d-------- C:\Lxk700
2008-06-23 10:29 . 2008-04-13 14:47 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 18:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-14 14:12 --------- d-----w C:\Program Files\PokerStars
2008-07-14 12:27 --------- d-----w C:\Program Files\CollectionsManager
2008-06-23 15:19 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:48 --------- d-----w C:\Program Files\XP Codec Pack
2008-06-13 13:41 --------- d-----w C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 18:57 --------- d-----w C:\Documents and Settings\user\Application Data\InterTrust
2008-06-12 18:56 --------- d-----w C:\Program Files\PowerPoint Viewer
2008-06-12 18:54 --------- d-----w C:\Program Files\Interactive Northwest
2008-06-12 18:51 --------- d-----w C:\Program Files\Common Files\Borland Shared
2008-06-12 18:51 --------- d-----w C:\Program Files\Avaya Solutions
2008-06-12 18:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-12 18:16 --------- d-----w C:\Program Files\Microsoft Works
2008-06-12 18:15 --------- d-----w C:\Program Files\MSBuild
2008-06-12 18:10 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-12 18:06 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-06-11 03:03 --------- d-----w C:\Program Files\PC Drivers HeadQuarters
2008-06-11 03:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-06-11 02:48 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-06-09 14:15 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-04-01 17:33 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-04-01 17:33 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-04-01 17:33 114688]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-01-20 03:05 217088]
"MWLExe"="C:\Program Files\Mcafee\MWL\MWLGui.exe" [2007-07-28 09:32 1279336]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 05:42 1164576]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2006-10-02 15:09 35928]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-07-09 17:33 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=cuecycyu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\McAfee\\MWL\\MwlSvc.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 TeamViewer;TeamViewer 3;C:\Program Files\TeamViewer3\TeamViewer_Host.exe [2008-06-20 07:14]
S2 0242671216814142mcinstcleanup;McAfee Application Installer Cleanup (0242671216814142);C:\WINDOWS\TEMP\024267~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-11-05 05:02]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{224b43e0-3767-11dd-a996-001422954985}]
\Shell\AutoRun\command - "F:\Install FreeAgent Tools.exe" /run
*Newly Created Service* - 0242671216814142MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder
"2008-06-26 17:11:33 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-06-26 17:11:26 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 -: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O16 -: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://cnn-5.vo.llnwd.net/c1/static/cab_headless/GameTapWebUpdater.cab
C:\WINDOWS\Downloaded Program Files\GameTapWebUpdater.inf
C:\WINDOWS\Downloaded Program Files\updater.csv
C:\WINDOWS\Downloaded Program Files\GameTapWebUpdater.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-23 08:24:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\SiteAdvisor\6261\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\TeamViewer3\TeamViewer.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-07-23 8:29:23 - machine was rebooted [sedin]
ComboFix-quarantined-files.txt 2008-07-23 12:29:09
Pre-Run: 29,163,446,272 bytes free
Post-Run: 29,123,944,448 bytes free
265 --- E O F --- 2008-07-15 19:25:02
this is my new hjt log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:35, on 2008-07-23
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\Program Files\TeamViewer3\TeamViewer_Host.exe
C:\Program Files\TeamViewer3\TeamViewer.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Mcafee\MWL\MWLGui.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [MWLExe] C:\Program Files\Mcafee\MWL\MWLGui.exe /Start
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} (GameTap Web Updater) - http://cnn-5.vo.llnwd.net/c1/static/cab_headless/GameTapWebUpdater.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Profilemanagement.local
O17 - HKLM\Software\..\Telephony: DomainName = Profilemanagement.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Profilemanagement.local
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: cuecycyu.dll
O23 - Service: McAfee Application Installer Cleanup (0242671216814142) (0242671216814142mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\024267~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: McAfee Wireless Network Security Service (MWLSvc) - McAfee, Inc. - C:\Program Files\Mcafee\MWL\MwlSvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
--
End of file - 7982 bytes
SMOKIN420311
2008-07-24, 22:14
ok i had problems with my macafee anti viruse i had to remove it and install avast i hope that does not cause any problems other than that i followed all directions her are the logs
ComboFix 08-07-23.5 - sedin 2008-07-24 12:52:04.2 - NTFSx86
Running from: C:\Documents and Settings\sedin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\sedin\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\cuecycyu.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
.
((((((((((((((((((((((((( Files Created from 2008-06-24 to 2008-07-24 )))))))))))))))))))))))))))))))
.
2008-07-24 12:43 . 2008-07-24 12:43 <DIR> d-------- C:\WINDOWS\LastGood
2008-07-23 16:51 . 2008-07-23 16:51 <DIR> d-------- C:\WINDOWS\Sun
2008-07-23 16:50 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-23 16:49 . 2008-07-23 16:50 <DIR> d-------- C:\Program Files\Java
2008-07-23 16:47 . 2008-07-23 16:47 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-23 16:43 . 2008-07-23 16:43 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-07-23 16:39 . 2008-07-23 16:39 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-07-23 16:39 . 2008-07-23 16:41 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-07-23 16:10 . 2008-07-23 16:10 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-23 16:03 . 2008-07-23 16:03 <DIR> d-------- C:\Documents and Settings\sedin\.jpi_cache
2008-07-23 16:03 . 2008-07-23 16:21 <DIR> d-------- C:\Documents and Settings\sedin\.java
2008-07-23 11:38 . 2008-07-23 11:38 <DIR> d-------- C:\Program Files\Alwil Software
2008-07-23 11:38 . 2003-03-18 17:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-07-23 11:38 . 2003-03-18 16:14 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-07-21 11:48 . 2008-07-21 12:28 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\Paltalk
2008-07-21 11:47 . 2008-07-21 11:47 <DIR> d-------- C:\WINDOWS\PaltalkScene
2008-07-21 11:47 . 2008-07-21 12:28 <DIR> d-------- C:\Program Files\Paltalk Messenger
2008-07-18 14:52 . 2008-07-18 14:52 <DIR> d-------- C:\Program Files\GameTap
2008-07-18 14:52 . 2008-07-18 15:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GameTap
2008-07-16 15:32 . 2008-07-16 15:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-16 13:53 . 2008-07-24 12:37 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-16 13:53 . 2008-07-24 12:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-16 11:03 . 2008-07-16 11:03 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-16 11:03 . 2008-07-16 11:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-16 08:30 . 2008-07-16 08:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-16 08:29 . 2008-07-23 08:11 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-16 08:29 . 2008-07-23 08:12 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\SUPERAntiSpyware.com
2008-07-16 08:21 . 2008-07-16 08:21 <DIR> d-------- C:\Documents and Settings\downloads\SUPERAntiSpyware Professional v4.15.1000 + Cracks [Lifetime Subscription]
2008-07-16 08:15 . 2008-07-23 08:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-15 14:45 . 2008-07-15 14:45 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-07-15 14:45 . 2008-07-15 14:45 <DIR> d-------- C:\WINDOWS\system32\en
2008-07-15 14:45 . 2008-07-15 14:45 <DIR> d-------- C:\WINDOWS\system32\bits
2008-07-15 14:45 . 2008-07-15 14:45 <DIR> d-------- C:\WINDOWS\l2schemas
2008-07-15 14:41 . 2008-07-15 14:46 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-07-15 14:28 . 2008-07-15 14:28 <DIR> d-------- C:\Program Files\Codec Pack - All In 1
2008-07-15 14:28 . 2008-07-15 14:26 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-07-15 12:40 . 2008-07-15 12:40 <DIR> d-------- C:\Documents and Settings\testuser\Application Data\TeamViewer
2008-07-15 12:37 . 2008-07-15 12:38 <DIR> d-------- C:\Documents and Settings\testuser
2008-07-15 08:59 . 2008-07-15 08:59 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\TeamViewer
2008-07-15 08:11 . 2008-07-15 08:11 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\TeamViewer
2008-07-15 08:11 . 2008-07-15 08:11 <DIR> d-------- C:\Program Files\TeamViewer3
2008-07-15 08:11 . 2008-07-15 08:13 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\TeamViewer
2008-07-15 08:10 . 2008-07-15 08:10 <DIR> d-------- C:\Documents and Settings\sedin\temp
2008-07-14 15:44 . 2008-07-14 15:44 <DIR> d-------- C:\Program Files\GameTap Web Player
2008-07-14 15:44 . 2008-07-14 15:44 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\InstallShield
2008-07-14 15:36 . 2008-07-14 15:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GameTap Web Player
2008-07-14 08:11 . 2008-07-14 08:12 <DIR> d-------- C:\Documents and Settings\collector
2008-07-10 14:24 . 2008-07-23 11:43 <DIR> d-------- C:\Documents and Settings\downloads\Microsoft .NET Framework 3.5
2008-07-10 14:07 . 2008-07-10 14:11 <DIR> d-------- C:\Documents and Settings\downloads\microsoft .netframework all version
2008-07-10 12:32 . 2008-07-10 12:32 <DIR> d-------- C:\WINDOWS\WinRAR
2008-07-10 11:54 . 2008-07-23 10:42 <DIR> d-------- C:\Documents and Settings\downloads
2008-07-10 11:48 . 2008-07-10 11:48 <DIR> d-------- C:\Program Files\uTorrent
2008-07-10 11:48 . 2008-07-16 08:24 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\uTorrent
2008-07-07 12:33 . 2008-07-22 08:53 <DIR> d-------- C:\Program Files\Winamp
2008-07-07 12:33 . 2008-07-22 08:52 <DIR> d-------- C:\Documents and Settings\sedin\Application Data\Winamp
2008-07-07 11:36 . 2008-04-13 15:17 83,072 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-07-07 11:36 . 2008-04-13 14:45 56,576 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-07-07 11:36 . 2008-04-13 14:45 52,864 --a------ C:\WINDOWS\system32\drivers\dmusic.sys
2008-07-07 11:36 . 2008-04-13 14:45 6,272 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-07-07 11:35 . 2008-04-13 14:45 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-07-07 11:35 . 2008-04-13 12:39 142,592 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-07-07 11:35 . 2008-04-13 15:15 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-07-07 11:35 . 2008-04-13 14:39 7,552 --a------ C:\WINDOWS\system32\drivers\mskssrv.sys
2008-07-07 11:35 . 2008-04-13 14:39 5,376 --a------ C:\WINDOWS\system32\drivers\mspclock.sys
2008-07-07 11:35 . 2008-04-13 14:39 4,992 --a------ C:\WINDOWS\system32\drivers\mspqm.sys
2008-07-07 11:35 . 2008-04-13 14:45 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2008-07-07 11:33 . 2007-05-10 10:23 4,952,064 --a------ C:\WINDOWS\system32\stacgui.cpl
2008-07-07 11:33 . 2007-04-10 17:02 1,601,536 --a------ C:\WINDOWS\system32\stlang.dll
2008-07-07 11:33 . 2007-05-10 10:22 405,504 --a------ C:\WINDOWS\stsystra.exe
2008-07-07 11:31 . 2008-04-13 20:12 129,536 --a------ C:\WINDOWS\system32\ksproxy.ax
2008-07-07 11:31 . 2008-04-13 14:45 60,160 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-07-07 11:31 . 2008-04-13 20:11 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-07-07 11:29 . 2008-07-07 11:29 <DIR> d-------- C:\Program Files\SigmaTel
2008-07-07 11:29 . 2007-05-10 10:24 1,222,840 --a------ C:\WINDOWS\system32\drivers\sthda.sys
2008-07-07 11:29 . 2007-05-10 10:23 270,336 --a------ C:\WINDOWS\system32\stacapi.dll
2008-07-07 11:29 . 2007-08-21 09:58 146,944 --a------ C:\WINDOWS\system32\st325602.dll
2008-07-07 11:28 . 2008-07-23 16:23 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-07-07 11:22 . 2008-07-07 11:22 <DIR> d-------- C:\WINDOWS\system32\Dell
2008-07-07 11:22 . 2008-07-07 11:22 <DIR> d-------- C:\Program Files\Dell
2008-07-07 10:58 . 2008-07-14 08:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CollectionsManager
2008-07-07 10:49 . 2008-07-07 10:49 <DIR> d-------- C:\Program Files\Microsoft Windows Small Business Server
2008-07-07 10:46 . 2008-07-24 12:36 <DIR> d-------- C:\Documents and Settings\sedin
2008-06-26 13:08 . 2008-07-23 10:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-06-26 13:03 . 2005-04-20 19:22 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-06-26 12:52 . 2008-07-23 10:44 <DIR> d-------- C:\Program Files\McAfee
2008-06-26 12:52 . 2008-07-23 10:44 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-06-26 12:51 . 2008-07-23 10:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-26 12:05 . 2008-06-26 12:05 <DIR> d-------- C:\Program Files\PowerISO
2008-06-26 11:03 . 2008-06-26 11:04 <DIR> d-------- C:\Documents and Settings\user\Application Data\Media Player Classic
2008-06-24 15:42 . 2008-04-13 14:45 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-24 15:42 . 2008-04-13 20:11 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-06-24 15:42 . 2008-04-13 14:39 14,592 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-23 20:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-14 14:12 --------- d-----w C:\Program Files\PokerStars
2008-07-14 12:27 --------- d-----w C:\Program Files\CollectionsManager
2008-06-23 15:19 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-23 14:44 --------- d-----w C:\Program Files\Lexmark Z700-P700 Series
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:48 --------- d-----w C:\Program Files\XP Codec Pack
2008-06-13 13:41 --------- d-----w C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 18:57 --------- d-----w C:\Documents and Settings\user\Application Data\InterTrust
2008-06-12 18:56 --------- d-----w C:\Program Files\PowerPoint Viewer
2008-06-12 18:54 --------- d-----w C:\Program Files\Interactive Northwest
2008-06-12 18:51 --------- d-----w C:\Program Files\Common Files\Borland Shared
2008-06-12 18:51 --------- d-----w C:\Program Files\Avaya Solutions
2008-06-12 18:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-12 18:16 --------- d-----w C:\Program Files\Microsoft Works
2008-06-12 18:15 --------- d-----w C:\Program Files\MSBuild
2008-06-12 18:10 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-12 18:06 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-06-11 03:03 --------- d-----w C:\Program Files\PC Drivers HeadQuarters
2008-06-11 03:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-06-11 02:48 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-06-09 14:15 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-09 10:53 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
2008-05-09 10:53 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:53 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((( snapshot@2008-07-23_ 8.28.41.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-24 23:33:02 1,527,056 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.2\FP_AX_CAB_INSTALLER.exe
- 2008-04-14 00:12:38 208,896 ----a-w C:\WINDOWS\inf\unregmp2.exe
+ 2006-11-01 22:31:34 315,904 ----a-w C:\WINDOWS\inf\unregmp2.exe
+ 2008-06-17 20:12:42 114,688 ----a-w C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
+ 2008-06-17 20:23:02 202,168 ----a-w C:\WINDOWS\system32\Adobe\Director\swdir.dll
+ 2008-06-17 20:23:18 62,904 ----a-w C:\WINDOWS\system32\Adobe\Director\SwDnld.exe
+ 2008-06-17 20:13:22 487,424 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Control.dll
+ 2008-06-17 19:36:00 1,798,144 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\dirapi.dll
+ 2008-06-17 20:13:26 9,216 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2008-06-17 19:25:58 697,344 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gi.dll
+ 2008-06-17 19:26:00 1,145,896 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gt.exe
+ 2008-06-17 19:25:58 52,288 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gtapi.dll
+ 2008-06-17 19:32:18 892,928 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\iml32.dll
+ 2008-06-17 20:11:56 253,952 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Plugin.dll
+ 2008-06-17 20:15:00 446,464 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Proj.dll
+ 2008-06-17 20:22:46 439,736 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1100458.exe
+ 2008-06-17 20:15:44 114,688 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwInit.exe
+ 2008-06-17 20:11:44 94,208 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2008-06-17 19:25:58 50,808 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 1999-06-25 14:55:30 149,504 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\UNWISE.EXE
- 2008-04-13 17:23:38 8,192 ----a-w C:\WINDOWS\system32\asferror.dll
+ 2006-10-19 01:47:08 7,168 ----a-w C:\WINDOWS\system32\asferror.dll
+ 2008-07-19 14:43:08 1,163,960 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2006-10-19 01:47:08 276,992 ------w C:\WINDOWS\system32\audiodev.dll
+ 2008-07-19 14:30:53 94,392 ----a-w C:\WINDOWS\system32\AvastSS.scr
- 2005-01-28 17:44:28 294,912 ----a-w C:\WINDOWS\system32\blackbox.dll
+ 2006-10-19 01:47:10 542,720 ----a-w C:\WINDOWS\system32\blackbox.dll
- 2005-01-28 17:44:28 164,864 ----a-w C:\WINDOWS\system32\cewmdm.dll
+ 2006-10-19 01:47:10 229,376 ----a-w C:\WINDOWS\system32\cewmdm.dll
- 2008-07-23 11:55:55 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-07-23 14:24:23 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-07-23 11:55:55 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-23 14:24:23 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-23 14:24:23 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-13 17:23:38 8,192 -c--a-w C:\WINDOWS\system32\dllcache\asferror.dll
+ 2006-10-19 01:47:08 7,168 -c--a-w C:\WINDOWS\system32\dllcache\asferror.dll
- 2005-01-28 17:44:28 294,912 -c--a-w C:\WINDOWS\system32\dllcache\blackbox.dll
+ 2006-10-19 01:47:10 542,720 -c--a-w C:\WINDOWS\system32\dllcache\blackbox.dll
- 2005-01-28 17:44:28 164,864 -c--a-w C:\WINDOWS\system32\dllcache\cewmdm.dll
+ 2006-10-19 01:47:10 229,376 -c--a-w C:\WINDOWS\system32\dllcache\cewmdm.dll
- 2005-01-28 17:44:28 502,272 -c--a-w C:\WINDOWS\system32\dllcache\drmv2clt.dll
+ 2006-10-19 01:47:10 991,744 -c--a-w C:\WINDOWS\system32\dllcache\drmv2clt.dll
- 2005-01-28 17:44:28 6,656 -c--a-w C:\WINDOWS\system32\dllcache\laprxy.dll
+ 2006-10-19 01:47:14 11,264 -c--a-w C:\WINDOWS\system32\dllcache\LAPRXY.dll
- 2005-01-28 17:44:28 96,768 -c--a-w C:\WINDOWS\system32\dllcache\logagent.exe
+ 2006-10-19 00:03:58 100,864 -c--a-w C:\WINDOWS\system32\dllcache\logagent.exe
- 2008-04-14 00:11:57 310,272 -c--a-w C:\WINDOWS\system32\dllcache\mp43dmod.dll
+ 2006-10-19 01:47:14 4,096 -c--a-w C:\WINDOWS\system32\dllcache\MP43DMOD.dll
- 2008-04-14 00:11:57 384,512 -c--a-w C:\WINDOWS\system32\dllcache\mp4sdmod.dll
+ 2006-10-19 01:47:14 4,096 -c--a-w C:\WINDOWS\system32\dllcache\MP4SDMOD.dll
- 2008-04-14 00:11:57 240,640 -c--a-w C:\WINDOWS\system32\dllcache\mpg4dmod.dll
+ 2006-10-19 01:47:14 4,096 -c--a-w C:\WINDOWS\system32\dllcache\MPG4DMOD.dll
- 2008-04-14 00:11:57 368,640 -c--a-w C:\WINDOWS\system32\dllcache\mpvis.dll
+ 2006-10-19 01:47:14 243,712 -c--a-w C:\WINDOWS\system32\dllcache\mpvis.dll
- 2005-01-28 17:44:28 142,336 -c--a-w C:\WINDOWS\system32\dllcache\msnetobj.dll
+ 2006-10-19 01:47:16 179,712 -c--a-w C:\WINDOWS\system32\dllcache\msnetobj.dll
- 2005-01-28 17:44:28 25,088 -c--a-w C:\WINDOWS\system32\dllcache\mspmsnsv.dll
+ 2006-10-19 01:47:16 27,136 -c--a-w C:\WINDOWS\system32\dllcache\mspmsnsv.dll
- 2005-01-28 17:44:28 173,568 -c--a-w C:\WINDOWS\system32\dllcache\mspmsp.dll
+ 2006-10-19 01:47:16 175,616 -c--a-w C:\WINDOWS\system32\dllcache\mspmsp.dll
- 2005-01-28 17:44:28 364,784 -c--a-w C:\WINDOWS\system32\dllcache\msscp.dll
+ 2006-10-19 01:47:16 414,208 -c--a-w C:\WINDOWS\system32\dllcache\msscp.dll
- 2005-01-28 17:44:28 315,904 -c--a-w C:\WINDOWS\system32\dllcache\mswmdm.dll
+ 2006-10-19 01:47:16 321,536 -c--a-w C:\WINDOWS\system32\dllcache\mswmdm.dll
- 2005-01-28 17:44:28 221,184 -c--a-w C:\WINDOWS\system32\dllcache\qasf.dll
+ 2006-10-19 01:47:18 211,456 -c--a-w C:\WINDOWS\system32\dllcache\qasf.dll
- 2008-04-14 00:12:35 774,144 -c--a-w C:\WINDOWS\system32\dllcache\setup_wm.exe
+ 2006-11-01 22:31:38 1,669,120 -c--a-w C:\WINDOWS\system32\dllcache\setup_wm.exe
- 2008-04-14 00:12:38 208,896 -c--a-w C:\WINDOWS\system32\dllcache\unregmp2.exe
+ 2006-11-01 22:31:34 315,904 -c--a-w C:\WINDOWS\system32\dllcache\unregmp2.exe
- 2005-01-28 17:44:28 396,528 -c--a-w C:\WINDOWS\system32\dllcache\wmadmod.dll
+ 2006-10-19 01:47:18 757,248 -c--a-w C:\WINDOWS\system32\dllcache\WMADMOD.dll
- 2005-01-28 17:44:28 716,288 -c--a-w C:\WINDOWS\system32\dllcache\wmadmoe.dll
+ 2006-10-19 01:47:18 1,117,696 -c--a-w C:\WINDOWS\system32\dllcache\WMADMOE.dll
- 2007-10-27 21:40:06 227,328 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
+ 2007-10-27 21:40:30 222,720 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
- 2005-01-28 17:44:28 28,160 -c--a-w C:\WINDOWS\system32\dllcache\wmdmlog.dll
+ 2006-10-19 01:47:18 33,792 -c--a-w C:\WINDOWS\system32\dllcache\wmdmlog.dll
- 2005-01-28 17:44:28 33,792 -c--a-w C:\WINDOWS\system32\dllcache\wmdmps.dll
+ 2006-10-19 01:47:18 37,376 -c--a-w C:\WINDOWS\system32\dllcache\wmdmps.dll
- 2008-04-13 17:23:24 168,448 -c--a-w C:\WINDOWS\system32\dllcache\wmerror.dll
+ 2006-10-19 01:47:20 227,328 -c--a-w C:\WINDOWS\system32\dllcache\wmerror.dll
- 2005-01-28 17:44:28 150,016 -c--a-w C:\WINDOWS\system32\dllcache\wmidx.dll
+ 2006-10-19 01:47:20 157,184 -c--a-w C:\WINDOWS\system32\dllcache\wmidx.dll
- 2005-01-28 17:44:28 1,027,072 -c--a-w C:\WINDOWS\system32\dllcache\wmnetmgr.dll
+ 2006-10-19 01:47:20 937,984 -c--a-w C:\WINDOWS\system32\dllcache\WMNetMgr.dll
- 2008-04-14 00:12:09 4,874,240 -c--a-w C:\WINDOWS\system32\dllcache\wmp.dll
+ 2006-10-19 01:47:20 10,834,432 -c--a-w C:\WINDOWS\system32\dllcache\wmp.dll
- 2008-04-14 00:12:09 114,688 -c--a-w C:\WINDOWS\system32\dllcache\wmpasf.dll
+ 2006-10-19 01:47:20 242,688 -c--a-w C:\WINDOWS\system32\dllcache\wmpasf.dll
- 2008-04-14 00:12:09 98,304 -c--a-w C:\WINDOWS\system32\dllcache\wmpband.dll
+ 2006-10-19 01:47:20 96,256 -c--a-w C:\WINDOWS\system32\dllcache\wmpband.dll
- 2008-04-14 00:12:09 233,472 -c--a-w C:\WINDOWS\system32\dllcache\wmpdxm.dll
+ 2006-10-19 01:47:20 314,880 -c--a-w C:\WINDOWS\system32\dllcache\wmpdxm.dll
- 2008-04-14 00:12:40 73,728 -c--a-w C:\WINDOWS\system32\dllcache\wmplayer.exe
+ 2006-10-19 01:46:20 64,000 -c--a-w C:\WINDOWS\system32\dllcache\wmplayer.exe
- 2008-04-13 17:28:21 2,940,928 -c--a-w C:\WINDOWS\system32\dllcache\wmploc.dll
+ 2006-10-19 01:47:20 8,231,936 -c--a-w C:\WINDOWS\system32\dllcache\wmploc.dll
- 2008-04-14 00:12:09 102,400 -c--a-w C:\WINDOWS\system32\dllcache\wmpshell.dll
+ 2006-10-19 01:47:20 99,840 -c--a-w C:\WINDOWS\system32\dllcache\wmpshell.dll
- 2005-01-28 17:44:28 774,904 -c--a-w C:\WINDOWS\system32\dllcache\wmsdmod.dll
+ 2006-10-19 01:47:22 4,096 -c--a-w C:\WINDOWS\system32\dllcache\wmsdmod.dll
- 2005-01-28 17:44:28 1,119,744 -c--a-w C:\WINDOWS\system32\dllcache\wmsdmoe2.dll
+ 2006-10-19 01:47:22 4,096 -c--a-w C:\WINDOWS\system32\dllcache\wmsdmoe2.dll
- 2005-01-28 17:44:28 413,944 -c--a-w C:\WINDOWS\system32\dllcache\wmspdmod.dll
+ 2006-10-19 01:47:22 603,648 -c--a-w C:\WINDOWS\system32\dllcache\WMSPDMOD.dll
- 2005-01-28 17:44:28 940,544 -c--a-w C:\WINDOWS\system32\dllcache\wmspdmoe.dll
+ 2006-10-19 01:47:22 1,329,152 -c--a-w C:\WINDOWS\system32\dllcache\WMSPDMOE.dll
- 2006-12-07 05:29:34 2,374,472 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
+ 2006-10-19 01:47:22 2,450,944 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
- 2005-01-28 17:44:28 895,736 -c--a-w C:\WINDOWS\system32\dllcache\wmvdmod.dll
+ 2006-10-19 01:47:22 4,096 -c--a-w C:\WINDOWS\system32\dllcache\wmvdmod.dll
- 2005-01-28 17:44:28 1,003,008 -c--a-w C:\WINDOWS\system32\dllcache\wmvdmoe2.dll
+ 2006-10-19 01:47:22 4,096 -c--a-w C:\WINDOWS\system32\dllcache\wmvdmoe2.dll
+ 2008-07-19 14:32:15 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-07-19 14:37:42 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-07-19 14:37:21 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-07-19 14:33:42 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-07-19 14:35:18 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-07-19 14:32:36 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2006-10-19 01:47:22 671,232 ------w C:\WINDOWS\system32\drivers\UMDF\wpdmtpdr.dll
- 2005-01-28 17:44:28 18,944 ----a-w C:\WINDOWS\system32\drivers\wpdusb.sys
+ 2006-10-19 00:00:00 38,528 ----a-w C:\WINDOWS\system32\drivers\wpdusb.sys
+ 2006-09-28 22:55:50 77,568 ------w C:\WINDOWS\system32\drivers\WudfPf.sys
+ 2006-09-28 23:00:34 82,944 ------w C:\WINDOWS\system32\drivers\WudfRd.sys
+ 2006-10-19 00:00:46 249,856 ------w C:\WINDOWS\system32\drmupgds.exe
- 2005-01-28 17:44:28 502,272 ----a-w C:\WINDOWS\system32\drmv2clt.dll
+ 2006-10-19 01:47:10 991,744 ----a-w C:\WINDOWS\system32\drmv2clt.dll
+ 2008-06-10 05:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 05:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 06:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
- 2005-01-28 17:44:28 6,656 ----a-w C:\WINDOWS\system32\laprxy.dll
+ 2006-10-19 01:47:14 11,264 ----a-w C:\WINDOWS\system32\LAPRXY.dll
- 2005-01-28 17:44:28 96,768 ----a-w C:\WINDOWS\system32\logagent.exe
+ 2006-10-19 00:03:58 100,864 ----a-w C:\WINDOWS\system32\logagent.exe
+ 2008-03-15 03:31:26 57,344 ----a-w C:\WINDOWS\system32\Macromed\Common\SwSupport.dll
- 2008-07-14 18:39:16 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-07-23 20:54:25 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-03-15 03:29:22 581,632 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll
+ 2008-03-15 03:12:30 1,490,944 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\dirapiX.dll
+ 2008-03-15 03:29:58 24,576 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\DynaPlayer.dll
+ 2008-03-15 03:10:06 606,208 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\iml32X.dll
+ 2008-03-15 03:28:48 339,968 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Plugin.dll
+ 2008-03-15 03:28:56 475,136 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\PluginPing.dll
+ 2008-03-15 03:21:52 180,224 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Proj.dll
+ 2008-03-15 03:31:28 77,824 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwInit.exe
+ 2008-03-15 15:38:08 86,016 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwMenuX.dll
+ 2008-03-15 03:31:28 98,304 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwOnce.dll
+ 2006-10-19 01:47:14 212,992 ------w C:\WINDOWS\system32\MFPLAT.dll
+ 2006-10-19 01:47:14 259,072 ------w C:\WINDOWS\system32\MP43DECD.dll
- 2008-04-14 00:11:57 310,272 ----a-w C:\WINDOWS\system32\mp43dmod.dll
+ 2006-10-19 01:47:14 4,096 ----a-w C:\WINDOWS\system32\MP43DMOD.dll
+ 2006-10-19 01:47:14 317,440 ------w C:\WINDOWS\system32\MP4SDECD.dll
- 2008-04-14 00:11:57 384,512 ----a-w C:\WINDOWS\system32\mp4sdmod.dll
+ 2006-10-19 01:47:14 4,096 ----a-w C:\WINDOWS\system32\MP4SDMOD.dll
+ 2006-10-19 01:47:14 259,072 ------w C:\WINDOWS\system32\MPG4DECD.dll
- 2008-04-14 00:11:57 240,640 ----a-w C:\WINDOWS\system32\mpg4dmod.dll
+ 2006-10-19 01:47:14 4,096 ----a-w C:\WINDOWS\system32\MPG4DMOD.dll
+ 2006-10-02 19:28:42 312,128 ------w C:\WINDOWS\system32\msdelta.dll
- 2005-01-28 17:44:28 142,336 ----a-w C:\WINDOWS\system32\msnetobj.dll
+ 2006-10-19 01:47:16 179,712 ----a-w C:\WINDOWS\system32\msnetobj.dll
- 2005-01-28 17:44:28 25,088 ----a-w C:\WINDOWS\system32\MsPMSNSv.dll
+ 2006-10-19 01:47:16 27,136 ----a-w C:\WINDOWS\system32\mspmsnsv.dll
- 2005-01-28 17:44:28 173,568 ----a-w C:\WINDOWS\system32\MsPMSP.dll
+ 2006-10-19 01:47:16 175,616 ----a-w C:\WINDOWS\system32\mspmsp.dll
- 2005-01-28 17:44:28 364,784 ----a-w C:\WINDOWS\system32\MSSCP.dll
+ 2006-10-19 01:47:16 414,208 ----a-w C:\WINDOWS\system32\msscp.dll
- 2005-01-28 17:44:28 315,904 ----a-w C:\WINDOWS\system32\MSWMDM.dll
+ 2006-10-19 01:47:16 321,536 ----a-w C:\WINDOWS\system32\mswmdm.dll
+ 2006-10-19 01:47:18 284,160 ------w C:\WINDOWS\system32\PortableDeviceApi.dll
+ 2006-10-19 01:47:18 101,888 ------w C:\WINDOWS\system32\PortableDeviceClassExtension.dll
+ 2006-10-19 01:47:18 166,912 ------w C:\WINDOWS\system32\PortableDeviceTypes.dll
+ 2006-10-19 01:47:18 132,096 ------w C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
+ 2006-10-19 01:47:18 199,168 ------w C:\WINDOWS\system32\PortableDeviceWMDRM.dll
- 2005-01-28 17:44:28 221,184 ----a-w C:\WINDOWS\system32\qasf.dll
+ 2006-10-19 01:47:18 211,456 ----a-w C:\WINDOWS\system32\qasf.dll
- 2007-11-30 12:39:22 17,272 ------w C:\WINDOWS\system32\spmsg.dll
+ 2006-09-25 21:58:48 14,640 ------w C:\WINDOWS\system32\spmsg.dll
- 2005-01-28 17:44:28 47,104 ----a-w C:\WINDOWS\system32\uwdf.exe
+ 2006-10-19 01:58:00 8,704 ----a-w C:\WINDOWS\system32\uwdf.exe
- 2005-01-28 17:44:28 15,872 ----a-w C:\WINDOWS\system32\wdfapi.dll
+ 2006-10-19 01:47:18 4,096 ----a-w C:\WINDOWS\system32\wdfapi.dll
- 2005-01-28 17:44:28 38,912 ----a-w C:\WINDOWS\system32\wdfmgr.exe
+ 2006-10-19 01:58:00 8,704 ----a-w C:\WINDOWS\system32\wdfmgr.exe
- 2005-01-28 17:44:28 396,528 ----a-w C:\WINDOWS\system32\wmadmod.dll
+ 2006-10-19 01:47:18 757,248 ----a-w C:\WINDOWS\system32\WMADMOD.dll
- 2005-01-28 17:44:28 716,288 ----a-w C:\WINDOWS\system32\wmadmoe.dll
+ 2006-10-19 01:47:18 1,117,696 ----a-w C:\WINDOWS\system32\WMADMOE.dll
- 2007-10-27 21:40:06 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
+ 2007-10-27 21:40:30 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
- 2005-01-28 17:44:28 28,160 ----a-w C:\WINDOWS\system32\WMDMLOG.dll
+ 2006-10-19 01:47:18 33,792 ----a-w C:\WINDOWS\system32\wmdmlog.dll
- 2005-01-28 17:44:28 33,792 ----a-w C:\WINDOWS\system32\WMDMPS.dll
+ 2006-10-19 01:47:18 37,376 ----a-w C:\WINDOWS\system32\wmdmps.dll
- 2005-01-28 17:44:28 335,872 ----a-w C:\WINDOWS\system32\WMDRMdev.dll
+ 2006-10-19 01:47:18 429,056 ----a-w C:\WINDOWS\system32\wmdrmdev.dll
- 2005-01-28 17:44:28 290,816 ----a-w C:\WINDOWS\system32\WMDRMNet.dll
+ 2006-10-19 01:47:20 348,672 ----a-w C:\WINDOWS\system32\wmdrmnet.dll
+ 2006-10-19 01:47:20 535,040 ------w C:\WINDOWS\system32\wmdrmsdk.dll
- 2008-04-13 17:23:24 168,448 ----a-w C:\WINDOWS\system32\wmerror.dll
+ 2006-10-19 01:47:20 227,328 ----a-w C:\WINDOWS\system32\wmerror.dll
- 2005-01-28 17:44:28 150,016 ----a-w C:\WINDOWS\system32\wmidx.dll
+ 2006-10-19 01:47:20 157,184 ----a-w C:\WINDOWS\system32\wmidx.dll
- 2005-01-28 17:44:28 1,027,072 ----a-w C:\WINDOWS\system32\wmnetmgr.dll
+ 2006-10-19 01:47:20 937,984 ----a-w C:\WINDOWS\system32\WMNetMgr.dll
- 2008-04-14 00:12:09 4,874,240 ----a-w C:\WINDOWS\system32\wmp.dll
+ 2006-10-19 01:47:20 10,834,432 ----a-w C:\WINDOWS\system32\wmp.dll
- 2008-04-14 00:12:09 114,688 ----a-w C:\WINDOWS\system32\wmpasf.dll
+ 2006-10-19 01:47:20 242,688 ----a-w C:\WINDOWS\system32\wmpasf.dll
- 2008-04-14 00:12:09 233,472 ----a-w C:\WINDOWS\system32\wmpdxm.dll
+ 2006-10-19 01:47:20 314,880 ----a-w C:\WINDOWS\system32\wmpdxm.dll
+ 2006-10-19 01:47:20 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
+ 2006-10-19 01:47:20 1,661,440 ------w C:\WINDOWS\system32\wmpencen.dll
- 2008-04-13 17:28:21 2,940,928 ----a-w C:\WINDOWS\system32\wmploc.dll
+ 2006-10-19 01:47:20 8,231,936 ----a-w C:\WINDOWS\system32\wmploc.dll
+ 2006-10-19 01:47:20 613,376 ------w C:\WINDOWS\system32\wmpmde.dll
+ 2006-10-19 01:47:20 130,048 ------w C:\WINDOWS\system32\wmpps.dll
- 2008-04-14 00:12:09 102,400 ----a-w C:\WINDOWS\system32\wmpshell.dll
+ 2006-10-19 01:47:20 99,840 ----a-w C:\WINDOWS\system32\wmpshell.dll
+ 2006-10-19 01:47:20 204,288 ------w C:\WINDOWS\system32\wmpsrcwp.dll
- 2005-01-28 17:44:28 774,904 ----a-w C:\WINDOWS\system32\wmsdmod.dll
+ 2006-10-19 01:47:22 4,096 ----a-w C:\WINDOWS\system32\wmsdmod.dll
- 2005-01-28 17:44:28 1,119,744 ----a-w C:\WINDOWS\system32\wmsdmoe2.dll
+ 2006-10-19 01:47:22 4,096 ----a-w C:\WINDOWS\system32\wmsdmoe2.dll
- 2005-01-28 17:44:28 413,944 ----a-w C:\WINDOWS\system32\wmspdmod.dll
+ 2006-10-19 01:47:22 603,648 ----a-w C:\WINDOWS\system32\WMSPDMOD.dll
- 2005-01-28 17:44:28 940,544 ----a-w C:\WINDOWS\system32\wmspdmoe.dll
+ 2006-10-19 01:47:22 1,329,152 ----a-w C:\WINDOWS\system32\WMSPDMOE.dll
- 2005-01-28 17:44:28 1,218,808 ----a-w C:\WINDOWS\system32\wmvadvd.dll
+ 2006-10-19 01:47:22 4,096 ----a-w C:\WINDOWS\system32\WMVADVD.dll
- 2005-01-28 17:44:28 1,512,448 ----a-w C:\WINDOWS\system32\WMVADVE.DLL
+ 2006-10-19 01:47:22 4,096 ----a-w C:\WINDOWS\system32\WMVADVE.DLL
- 2006-12-07 05:29:34 2,374,472 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2006-10-19 01:47:22 2,450,944 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2006-10-19 01:47:22 1,543,680 ------w C:\WINDOWS\system32\WMVDECOD.dll
- 2005-01-28 17:44:28 895,736 ----a-w C:\WINDOWS\system32\wmvdmod.dll
+ 2006-10-19 01:47:22 4,096 ----a-w C:\WINDOWS\system32\wmvdmod.dll
- 2005-01-28 17:44:28 1,003,008 ----a-w C:\WINDOWS\system32\wmvdmoe2.dll
+ 2006-10-19 01:47:22 4,096 ----a-w C:\WINDOWS\system32\wmvdmoe2.dll
+ 2006-10-19 01:47:22 1,574,912 ------w C:\WINDOWS\system32\WMVENCOD.dll
+ 2006-10-19 01:47:22 1,382,912 ------w C:\WINDOWS\system32\WMVSDECD.dll
+ 2006-10-19 01:47:22 767,488 ------w C:\WINDOWS\system32\WMVSENCD.dll
+ 2006-10-19 01:47:22 656,896 ------w C:\WINDOWS\system32\WMVXENCD.dll
- 2005-01-28 17:44:28 38,912 ----a-w C:\WINDOWS\system32\wpd_ci.dll
+ 2006-10-19 01:47:22 629,760 ----a-w C:\WINDOWS\system32\wpd_ci.dll
- 2005-01-28 17:44:28 61,952 ----a-w C:\WINDOWS\system32\wpdconns.dll
+ 2006-10-19 01:47:22 35,840 ----a-w C:\WINDOWS\system32\wpdconns.dll
- 2005-01-28 17:44:28 114,176 ----a-w C:\WINDOWS\system32\wpdmtp.dll
+ 2006-10-19 01:47:22 154,624 ----a-w C:\WINDOWS\system32\wpdmtp.dll
- 2005-01-28 17:44:28 66,560 ----a-w C:\WINDOWS\system32\wpdmtpus.dll
+ 2006-10-19 01:47:22 63,488 ----a-w C:\WINDOWS\system32\wpdmtpus.dll
+ 2006-10-19 01:47:22 2,603,008 ------w C:\WINDOWS\system32\WpdShext.dll
+ 2006-10-19 00:00:14 17,408 ------w C:\WINDOWS\system32\wpdshextautoplay.exe
+ 2006-10-19 01:47:22 38,400 ------w C:\WINDOWS\system32\wpdshextres.dll
+ 2006-10-19 01:47:22 133,632 ------w C:\WINDOWS\system32\WPDShServiceObj.dll
- 2005-01-28 17:44:28 331,264 ----a-w C:\WINDOWS\system32\wpdsp.dll
+ 2006-10-19 01:47:22 356,352 ----a-w C:\WINDOWS\system32\wpdsp.dll
+ 2006-09-29 00:13:26 95,344 ------w C:\WINDOWS\system32\WUDFCoinstaller.dll
+ 2006-09-28 22:56:38 146,432 ------w C:\WINDOWS\system32\WudfHost.exe
+ 2006-09-28 22:56:16 165,376 ------w C:\WINDOWS\system32\WudfPlatform.dll
+ 2006-09-28 22:56:14 55,808 ------w C:\WINDOWS\system32\WudfSvc.dll
+ 2006-09-28 22:56:38 316,416 ------w C:\WINDOWS\system32\WUDFx.dll
+ 2008-07-23 20:25:11 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5a8.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-04-01 17:33 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-04-01 17:33 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-04-01 17:33 114688]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-01-20 03:05 217088]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-07-09 17:33 36352]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 10:38 78008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 10:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 10:37]
R2 TeamViewer;TeamViewer 3;C:\Program Files\TeamViewer3\TeamViewer_Host.exe [2008-06-20 07:14]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-11-05 05:02]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{224b43e0-3767-11dd-a996-001422954985}]
\Shell\AutoRun\command - "F:\Install FreeAgent Tools.exe" /run
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-24 12:54:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-24 12:56:35
ComboFix-quarantined-files.txt 2008-07-24 16:56:27
ComboFix2.txt 2008-07-23 12:29:25
Pre-Run: 31,720,075,264 bytes free
Post-Run: 31,767,384,064 bytes free
467 --- E O F --- 2008-07-24 16:43:34
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:10, on 2008-07-24
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\TeamViewer3\TeamViewer_Host.exe
C:\Program Files\TeamViewer3\TeamViewer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1216846090413&h=a32c0b10ce2bc20d172d1a71d0d4d509/&filename=jinstall-6u7-windows-i586-jc.cab
O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} (GameTap Web Updater) - http://cnn-5.vo.llnwd.net/c1/static/cab_headless/GameTapWebUpdater.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Profilemanagement.local
O17 - HKLM\Software\..\Telephony: DomainName = Profilemanagement.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Profilemanagement.local
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
--
End of file - 6705 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2008-07-24 15:06
Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 24/07/2008
Kaspersky Anti-Virus database records: 1003763
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 40355
Number of viruses found: 1
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 00:44:05
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\downloads\Microsoft .NET Framework 3.5.rar/Microsoft .NET Framework 3.5/dotnetfx35setup.exe Infected: Trojan-Downloader.Win32.Agent.vtj skipped
C:\Documents and Settings\downloads\Microsoft .NET Framework 3.5.rar RAR: infected - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\sedin\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\sedin\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Documents and Settings\sedin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\sedin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\sedin\Local Settings\Application Data\Microsoft\Windows Media\11.0\WMSDKNSD.XML Object is locked skipped
C:\Documents and Settings\sedin\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\sedin\Local Settings\temp\~DFD942.tmp Object is locked skipped
C:\Documents and Settings\sedin\Local Settings\temp\~DFD956.tmp Object is locked skipped
C:\Documents and Settings\sedin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\sedin\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\sedin\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\selfdef.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\TeamViewer3\TeamViewer3_Logfile.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{3BB6DE66-A9C9-4032-A093-66B0AA212080}\RP54\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{E2197DD1-105E-449F-A32C-9E48E1ABB478}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_5a8.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.