ytic04
2011-03-17, 14:37
My computer seems to have been taken over by AVG Fake and i cannot remove it. It has bypassed the McAfee security and i cannot access the internet either. I have ran a full virus scan and nothing shown up.
I have not clicked any AVG links and have put the computer into safe mode.
Do you know how much information this virus has access to, as i do my banking and paypal accounts on this computer?
How do i remove it?
Thanks.
Sorry i did not get back to my computer before my original thread was removed. Since then i have followed instructions found on the net and managed to remove some of the virus as i can now get on the net and the pop ups have stopped. I think i removed something in win32 called debugger.
Any help to check if this has been successful would be well appreciated.
I have attached the attach.txt and paste DDS.txt
Thanks.
DDS (Ver_11-03-05.01) - NTFSx86 NETWORK
Run by colin at 12:19:13.42 on 17/03/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.699 [GMT 0:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\colin\Local Settings\Temporary Internet Files\Content.IE5\K3Z4ZPUA\dds[1].scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.skybroadband.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uWindow Title = Internet Explorer Provided By Sky Broadband
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: IEPlugin Class: {11222041-111b-46e3-bd29-efb2449479b1} - c:\progra~1\intern~2\ARCURL~1.DLL
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101110130630.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [PcSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AVG Antivirus 2011] c:\program files\avg antivirus 2011\avg.exe
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~3.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; Sky Broadband; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.myfootballgames.co.uk/game/141/3D-Penalty.html"
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [CTXFIREG] CTxfiReg.exe
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [Motive SmartBridge] c:\progra~1\ntl\broadb~1\smartb~1\MotiveSB.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\broadb~1.lnk - c:\program files\ntl\broadband medic\bin\matcli.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\philip~1.lnk - c:\program files\philips\gogear vibe device manager\GoGear_Vibe_DeviceManager.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://homebase.2020.net/Core/Player/2020PlayerAX_Win32.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192981567984
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
IFEO: chrome.exe - iesafemode.exe -sb
IFEO: firefox.exe - iesafemode.exe -sb
IFEO: opera.exe - iesafemode.exe -sb
IFEO: safari.exe - iesafemode.exe -sb
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-10-27 386840]
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2010-10-3 59240]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-10-27 84072]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-27 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-10-27 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-10-27 141792]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-10-27 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-10-27 88544]
S1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [2010-3-6 390528]
S1 RapportCerberus_23945;RapportCerberus_23945;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\23945\RapportCerberus_23945.sys [2011-3-1 55224]
S1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-10-3 169320]
S2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\printer\center\KodakSvc.exe [2008-2-15 18944]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2010-5-3 203280]
S2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-27 271480]
S2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-27 271480]
S2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-10-27 171168]
S2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-10-3 767208]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-10-27 55840]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-1-23 13352]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-10-27 152960]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-10-27 52104]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-10-27 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-10-27 84264]
.
=============== Created Last 30 ================
.
2011-03-14 15:04:54 -------- d-----w- c:\windows\LastGood.Tmp
.
==================== Find3M ====================
.
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 21:40:23 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-02 19:19:39 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-26 12:37:19 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-12-26 12:37:19 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59:19 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59:19 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55:26 385024 ----a-w- c:\windows\system32\html.iec
2009-11-06 17:02:38 720896 ----a-w- c:\program files\MediaConverter.exe
2009-08-06 10:25:44 102400 ----a-w- c:\program files\PortableDevice.dll
2009-05-26 19:05:58 204800 ----a-w- c:\program files\uMediaExport.dll
2009-05-04 19:37:40 335872 ----a-w- c:\program files\uMediaImport.dll
2009-04-29 09:19:10 237568 ----a-w- c:\program files\uMediaClub.dll
2009-04-22 15:13:18 92672 ----a-w- c:\program files\MagUIInter.dll
2009-04-22 15:13:14 104960 ----a-w- c:\program files\MagUIImage.dll
2009-04-22 15:13:12 305664 ----a-w- c:\program files\MagUIEngine.dll
2009-04-22 15:13:10 55808 ----a-w- c:\program files\MagPCMac.dll
2009-04-22 15:13:06 55808 ----a-w- c:\program files\MagicFrame.dll
2009-04-22 15:13:04 35328 ----a-w- c:\program files\MagCore.dll
2009-04-08 16:38:52 217088 ----a-w- c:\program files\ImportDVD.dll
2009-03-02 17:32:40 122880 ----a-w- c:\program files\smv.dll
2009-02-26 13:55:44 188416 ----a-w- c:\program files\uMediaInfo.dll
2009-02-26 13:52:52 147456 ----a-w- c:\program files\MPEGParser.dll
2009-02-24 18:39:50 176128 ----a-w- c:\program files\RemovableDevice.dll
2009-02-24 18:39:46 86016 ----a-w- c:\program files\ArcMDM.dll
2009-02-24 18:39:46 106496 ----a-w- c:\program files\WindowsMobile.dll
2009-02-06 09:32:06 122880 ----a-w- c:\program files\Res_AMC.dll
2009-01-14 10:16:32 760320 ----a-w- c:\program files\ToolsCtrl.dll
2009-01-14 10:16:18 125440 ----a-w- c:\program files\magPltfm.dll
2009-01-14 10:13:46 158208 ----a-w- c:\program files\magFileIO.dll
2009-01-14 10:13:44 436736 ----a-w- c:\program files\magFpxio.dll
2009-01-14 10:13:20 354816 ----a-w- c:\program files\magengin.dll
2009-01-14 10:13:18 88576 ----a-w- c:\program files\ImgCtrl.dll
2009-01-14 10:13:16 457216 ----a-w- c:\program files\magTools.dll
2008-12-12 11:12:00 1030656 ----a-w- c:\program files\RawEngine.dll
2008-11-28 15:38:06 80384 ----a-w- c:\program files\MagAppFramework.dll
2008-10-31 17:49:02 1150976 ----a-w- c:\program files\uDXPubTool.dll
2008-10-31 13:54:30 1642496 ----a-w- c:\program files\ArcSurface.dll
2008-10-07 16:32:00 61532 ----a-w- c:\program files\uASFWriter.dll
2008-09-23 13:50:00 73728 ----a-w- c:\program files\vedGrabber.dll
2008-08-28 13:48:08 278528 ----a-w- c:\program files\MP3Writer.DLL
2008-07-04 17:06:16 1792512 ----a-w- c:\program files\uVDibTool.dll
2008-07-04 17:06:14 59904 ----a-w- c:\program files\arcRmaImpDll.dll
2008-07-04 17:06:14 55808 ----a-w- c:\program files\uWMFDll2.dll
2008-07-04 17:06:12 109056 ----a-w- c:\program files\arcRmaPrvDll.dll
2008-07-04 17:06:10 84480 ----a-w- c:\program files\arcSamiDll.dll
2008-07-04 17:06:06 236032 ----a-w- c:\program files\uASF_SDK.dll
2008-07-04 17:06:02 174592 ----a-w- c:\program files\uaudioplyDll.dll
2008-02-14 09:15:34 864256 ----a-w- c:\program files\DevIL.dll
2008-02-14 09:15:34 81920 ----a-w- c:\program files\ILU.dll
2008-02-14 09:15:34 36864 ----a-w- c:\program files\ILUT.dll
2008-02-14 09:15:34 270336 ----a-w- c:\program files\libsndfile.dll
2007-12-26 11:26:54 35584 ----a-w- c:\program files\ExtrasCtrl.dll
2007-08-28 11:32:46 114688 ----a-w- c:\program files\MagAutoTest.dll
2007-05-09 18:03:56 256768 ----a-w- c:\program files\kgl.dll
2007-02-09 14:47:28 57344 ----a-w- c:\program files\uMsgDll.dll
2006-11-08 14:54:14 895744 ----a-w- c:\program files\uEzDll.dll
2006-11-08 14:54:12 436992 ----a-w- c:\program files\FPXLIB.DLL
2006-10-23 11:58:26 81920 ----a-w- c:\program files\Symbian60.dll
2006-09-07 16:04:52 372736 ----a-w- c:\program files\uEXIF.dll
2006-01-24 10:20:00 1645320 ----a-w- c:\program files\GdiPlus.dll
2005-12-07 11:37:00 45056 ----a-w- c:\program files\uaswmf.dll
2003-03-18 22:12:12 1047552 ----a-w- c:\program files\MFC71U.dll
1995-07-31 13:44:00 212480 ----a-w- c:\program files\PCDLIB32.DLL
.
============= FINISH: 12:19:34.64 ===============
I have not clicked any AVG links and have put the computer into safe mode.
Do you know how much information this virus has access to, as i do my banking and paypal accounts on this computer?
How do i remove it?
Thanks.
Sorry i did not get back to my computer before my original thread was removed. Since then i have followed instructions found on the net and managed to remove some of the virus as i can now get on the net and the pop ups have stopped. I think i removed something in win32 called debugger.
Any help to check if this has been successful would be well appreciated.
I have attached the attach.txt and paste DDS.txt
Thanks.
DDS (Ver_11-03-05.01) - NTFSx86 NETWORK
Run by colin at 12:19:13.42 on 17/03/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.699 [GMT 0:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\colin\Local Settings\Temporary Internet Files\Content.IE5\K3Z4ZPUA\dds[1].scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.skybroadband.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uWindow Title = Internet Explorer Provided By Sky Broadband
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: IEPlugin Class: {11222041-111b-46e3-bd29-efb2449479b1} - c:\progra~1\intern~2\ARCURL~1.DLL
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101110130630.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [PcSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AVG Antivirus 2011] c:\program files\avg antivirus 2011\avg.exe
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~3.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; Sky Broadband; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.myfootballgames.co.uk/game/141/3D-Penalty.html"
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [CTXFIREG] CTxfiReg.exe
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [Motive SmartBridge] c:\progra~1\ntl\broadb~1\smartb~1\MotiveSB.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\broadb~1.lnk - c:\program files\ntl\broadband medic\bin\matcli.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\philip~1.lnk - c:\program files\philips\gogear vibe device manager\GoGear_Vibe_DeviceManager.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://homebase.2020.net/Core/Player/2020PlayerAX_Win32.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192981567984
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
IFEO: chrome.exe - iesafemode.exe -sb
IFEO: firefox.exe - iesafemode.exe -sb
IFEO: opera.exe - iesafemode.exe -sb
IFEO: safari.exe - iesafemode.exe -sb
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-10-27 386840]
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2010-10-3 59240]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-10-27 84072]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-27 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-10-27 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-10-27 141792]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-10-27 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-10-27 88544]
S1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [2010-3-6 390528]
S1 RapportCerberus_23945;RapportCerberus_23945;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\23945\RapportCerberus_23945.sys [2011-3-1 55224]
S1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-10-3 169320]
S2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\printer\center\KodakSvc.exe [2008-2-15 18944]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2010-5-3 203280]
S2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-27 271480]
S2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-27 271480]
S2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-10-27 171168]
S2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-10-3 767208]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-10-27 55840]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-1-23 13352]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-10-27 152960]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-10-27 52104]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-10-27 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-10-27 84264]
.
=============== Created Last 30 ================
.
2011-03-14 15:04:54 -------- d-----w- c:\windows\LastGood.Tmp
.
==================== Find3M ====================
.
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 21:40:23 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-02 19:19:39 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-26 12:37:19 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-12-26 12:37:19 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59:19 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59:19 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55:26 385024 ----a-w- c:\windows\system32\html.iec
2009-11-06 17:02:38 720896 ----a-w- c:\program files\MediaConverter.exe
2009-08-06 10:25:44 102400 ----a-w- c:\program files\PortableDevice.dll
2009-05-26 19:05:58 204800 ----a-w- c:\program files\uMediaExport.dll
2009-05-04 19:37:40 335872 ----a-w- c:\program files\uMediaImport.dll
2009-04-29 09:19:10 237568 ----a-w- c:\program files\uMediaClub.dll
2009-04-22 15:13:18 92672 ----a-w- c:\program files\MagUIInter.dll
2009-04-22 15:13:14 104960 ----a-w- c:\program files\MagUIImage.dll
2009-04-22 15:13:12 305664 ----a-w- c:\program files\MagUIEngine.dll
2009-04-22 15:13:10 55808 ----a-w- c:\program files\MagPCMac.dll
2009-04-22 15:13:06 55808 ----a-w- c:\program files\MagicFrame.dll
2009-04-22 15:13:04 35328 ----a-w- c:\program files\MagCore.dll
2009-04-08 16:38:52 217088 ----a-w- c:\program files\ImportDVD.dll
2009-03-02 17:32:40 122880 ----a-w- c:\program files\smv.dll
2009-02-26 13:55:44 188416 ----a-w- c:\program files\uMediaInfo.dll
2009-02-26 13:52:52 147456 ----a-w- c:\program files\MPEGParser.dll
2009-02-24 18:39:50 176128 ----a-w- c:\program files\RemovableDevice.dll
2009-02-24 18:39:46 86016 ----a-w- c:\program files\ArcMDM.dll
2009-02-24 18:39:46 106496 ----a-w- c:\program files\WindowsMobile.dll
2009-02-06 09:32:06 122880 ----a-w- c:\program files\Res_AMC.dll
2009-01-14 10:16:32 760320 ----a-w- c:\program files\ToolsCtrl.dll
2009-01-14 10:16:18 125440 ----a-w- c:\program files\magPltfm.dll
2009-01-14 10:13:46 158208 ----a-w- c:\program files\magFileIO.dll
2009-01-14 10:13:44 436736 ----a-w- c:\program files\magFpxio.dll
2009-01-14 10:13:20 354816 ----a-w- c:\program files\magengin.dll
2009-01-14 10:13:18 88576 ----a-w- c:\program files\ImgCtrl.dll
2009-01-14 10:13:16 457216 ----a-w- c:\program files\magTools.dll
2008-12-12 11:12:00 1030656 ----a-w- c:\program files\RawEngine.dll
2008-11-28 15:38:06 80384 ----a-w- c:\program files\MagAppFramework.dll
2008-10-31 17:49:02 1150976 ----a-w- c:\program files\uDXPubTool.dll
2008-10-31 13:54:30 1642496 ----a-w- c:\program files\ArcSurface.dll
2008-10-07 16:32:00 61532 ----a-w- c:\program files\uASFWriter.dll
2008-09-23 13:50:00 73728 ----a-w- c:\program files\vedGrabber.dll
2008-08-28 13:48:08 278528 ----a-w- c:\program files\MP3Writer.DLL
2008-07-04 17:06:16 1792512 ----a-w- c:\program files\uVDibTool.dll
2008-07-04 17:06:14 59904 ----a-w- c:\program files\arcRmaImpDll.dll
2008-07-04 17:06:14 55808 ----a-w- c:\program files\uWMFDll2.dll
2008-07-04 17:06:12 109056 ----a-w- c:\program files\arcRmaPrvDll.dll
2008-07-04 17:06:10 84480 ----a-w- c:\program files\arcSamiDll.dll
2008-07-04 17:06:06 236032 ----a-w- c:\program files\uASF_SDK.dll
2008-07-04 17:06:02 174592 ----a-w- c:\program files\uaudioplyDll.dll
2008-02-14 09:15:34 864256 ----a-w- c:\program files\DevIL.dll
2008-02-14 09:15:34 81920 ----a-w- c:\program files\ILU.dll
2008-02-14 09:15:34 36864 ----a-w- c:\program files\ILUT.dll
2008-02-14 09:15:34 270336 ----a-w- c:\program files\libsndfile.dll
2007-12-26 11:26:54 35584 ----a-w- c:\program files\ExtrasCtrl.dll
2007-08-28 11:32:46 114688 ----a-w- c:\program files\MagAutoTest.dll
2007-05-09 18:03:56 256768 ----a-w- c:\program files\kgl.dll
2007-02-09 14:47:28 57344 ----a-w- c:\program files\uMsgDll.dll
2006-11-08 14:54:14 895744 ----a-w- c:\program files\uEzDll.dll
2006-11-08 14:54:12 436992 ----a-w- c:\program files\FPXLIB.DLL
2006-10-23 11:58:26 81920 ----a-w- c:\program files\Symbian60.dll
2006-09-07 16:04:52 372736 ----a-w- c:\program files\uEXIF.dll
2006-01-24 10:20:00 1645320 ----a-w- c:\program files\GdiPlus.dll
2005-12-07 11:37:00 45056 ----a-w- c:\program files\uaswmf.dll
2003-03-18 22:12:12 1047552 ----a-w- c:\program files\MFC71U.dll
1995-07-31 13:44:00 212480 ----a-w- c:\program files\PCDLIB32.DLL
.
============= FINISH: 12:19:34.64 ===============