Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: Windows Recovery Malware

  1. #1
    Member
    Join Date
    Apr 2011
    Posts
    78

    Default Windows Recovery Malware

    A "Windows Recovery" utility popped up on my machine, started scanning, and then reported infections. Having never installed anything called " Windows Recovery" I was suspicious, so I ran Spybot. It found a few things and I removed them, but on reboot I lost all desktop icons except 2 and "explore" only showed the Documents and Settings directory. I was finally able to force System Restore, but all of my desktop icons and files within explore showed up as "hidden". I was able to fix that with a utility called "unhide.exe". I'd like to make sure that I don't have any other bugs on the machine. Can anyone help me make sure that my computer is clean?

    Thank you.
    Paul

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Bob at 7:32:23.31 on Sun 04/24/2011
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1143 [GMT -5:00]
    .
    AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
    C:\WINDOWS\system32\svchost.exe -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\AVG\AVG10\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\AVG\AVG10\avgnsx.exe
    C:\Program Files\AVG\AVG10\avgemcx.exe
    C:\Program Files\Norton Ghost\Agent\VProSvc.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Norton Ghost\Agent\VProTray.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\My Lockbox\mylbx.exe
    C:\Program Files\AVG\AVG10\avgtray.exe
    C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
    C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
    C:\Program Files\DAEMON Tools Lite\DTLite.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
    C:\Program Files\AVG\AVG10\avgcsrvx.exe
    C:\PROGRA~1\AVG\AVG10\avgrsx.exe
    C:\Program Files\AVG\AVG10\avgcsrvx.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Documents and Settings\Bob\Desktop\dds.scr
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://twitter.com/
    uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=%s
    mURLSearchHooks: H - No File
    BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 7\SnagItBHO.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
    TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 7\SnagItIEAddin.dll
    TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
    TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
    uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe
    uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup
    uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized
    uRun: [OpenDNS Updater] "c:\program files\opendns updater\OpenDNSUpdater.exe" /autostart
    uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
    uRun: [0EBC39E44532BFFB] c:\upsd\upsd.exe
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [CloneCDTray] "c:\program files\slysoft\clonecd\CloneCDTray.exe" /s
    mRun: [EPSON Stylus CX3800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [AdobeVersionCue] c:\program files\adobe\adobe version cue\controlpanel\VersionCueTray.exe
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [Norton Ghost 14.0] "c:\program files\norton ghost\agent\VProTray.exe"
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
    mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [mylbx] c:\program files\my lockbox\mylbx.exe /a
    mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
    StartupFolder: c:\docume~1\bob\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\bob\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\FINDFAST.EXE
    StartupFolder: c:\docume~1\bob\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\adobe acrobat 6.0\distillr\acrotray.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\omegar~1.lnk - c:\program files\omega research\program\orschd.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\paltalk.lnk - c:\program files\paltalk messenger\paltalk.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - c:\program files\plotsoft\pdfill\DownloadPDF.exe
    IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {254AA86E-5655-4518-AA87-185D7CC41801} - hxxps://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
    Notify: igfxcui - igfxdev.dll
    Notify: LMIinit - LMIinit.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\docume~1\bob\applic~1\mozilla\firefox\profiles\vw9a9lod.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=685749&p=
    FF - component: c:\documents and settings\bob\application data\mozilla\firefox\profiles\vw9a9lod.default\extensions\dttoolbar@toolbarnet.com\components\DTToolbarFF.dll
    FF - component: c:\documents and settings\bob\application data\mozilla\firefox\profiles\vw9a9lod.default\extensions\twitternotifier@naan.net\platform\winnt\components\nsTwitterFoxSign.dll
    FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
    FF - plugin: c:\documents and settings\bob\application data\mozilla\firefox\profiles\vw9a9lod.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\np32dsw.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\NPDOC.DLL
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npdrmv2.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npdsplay.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\NPJPI142_06.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nppdf32.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nppl3260.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nprfxins.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nprjplug.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nprpjplug.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\NPSVG3.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npwmsdrm.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npyacs.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
    FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
    FF - Ext: Echofon: twitternotifier@naan.net - %profile%\extensions\twitternotifier@naan.net
    FF - Ext: PDF Download: {37E4D8EA-8BDA-4831-8EA1-89053939A250} - %profile%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
    FF - Ext: Ant Video Downloader: anttoolbar@ant.com - %profile%\extensions\anttoolbar@ant.com
    FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
    FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg10\Firefox4
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: capability.policy.policynames - allowclipboard
    FF - user.js: capability.policy.allowclipboard.sites - hxxp://www.insidefutures.com http://www.futuresknowledge.com
    FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
    FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32464]
    R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [2011-4-6 41912]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 296400]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-2-15 7421280]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
    R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2010-10-5 374152]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-1-27 12856]
    R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-7-13 47640]
    R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2004-8-4 5120]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134480]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216]
    R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2007-12-20 1553896]
    R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [2009-5-10 127496]
    S0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys --> c:\windows\system32\drivers\avgarkt.sys [?]
    S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
    S1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\avgarcln.sys --> c:\windows\system32\drivers\AvgArCln.sys [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" --> c:\program files\lavasoft\ad-aware\AAWService.exe [?]
    S3 NLNdisMP;NLNdisMP;c:\windows\system32\drivers\nlndis.sys --> c:\windows\system32\drivers\nlndis.sys [?]
    S3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\drivers\nlndis.sys --> c:\windows\system32\drivers\nlndis.sys [?]
    S4 LMIRfsClientNP;LMIRfsClientNP; [x]
    .
    =============== Created Last 30 ================
    .
    2011-04-18 12:18:19 -------- d-----w- c:\docume~1\alluse~1\applic~1\aAe06511eMbCp06511
    2011-04-14 14:56:23 -------- d-----w- c:\docume~1\alluse~1\applic~1\jPm06504jIdHj06504
    2011-04-12 17:13:16 -------- d-----w- c:\docume~1\alluse~1\applic~1\gJm06511lGnOa06511
    2011-04-12 16:28:47 -------- d-----w- c:\docume~1\bob\locals~1\applic~1\CRLCommonVdm
    2011-04-12 11:10:36 -------- d-----w- c:\docume~1\bob\applic~1\IObit
    2011-04-11 12:57:38 -------- d-----w- c:\docume~1\bob\applic~1\AVG10
    2011-04-11 12:55:33 -------- d-----w- c:\windows\system32\drivers\AVG
    2011-04-11 12:55:33 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVG10
    2011-04-11 12:23:21 -------- d-----w- c:\docume~1\alluse~1\applic~1\MFAData
    2011-04-11 10:40:43 -------- d-----w- c:\program files\ESET
    2011-04-10 21:40:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-04-10 21:40:16 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-04-10 21:40:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-04-10 19:49:03 -------- d-----w- C:\ComboFix
    2011-04-10 13:13:23 -------- d-sha-r- C:\cmdcons
    2011-04-10 13:09:33 98816 ----a-w- c:\windows\sed.exe
    2011-04-10 13:09:33 89088 ----a-w- c:\windows\MBR.exe
    2011-04-10 13:09:33 256512 ----a-w- c:\windows\PEV.exe
    2011-04-10 13:09:33 161792 ----a-w- c:\windows\SWREG.exe
    2011-04-09 22:00:34 -------- d-----w- c:\docume~1\bob\applic~1\AVG9
    2011-04-09 15:12:45 -------- d-----w- c:\docume~1\alluse~1\applic~1\bBe14005kFaLe14005
    2011-04-06 19:43:01 -------- d-----w- C:\wkep
    2011-04-06 19:37:26 -------- d-----w- C:\My Lockbox
    2011-04-06 19:37:02 41912 ----a-w- c:\windows\system32\drivers\FSPFltd.sys
    2011-04-06 17:33:43 -------- d-----w- c:\docume~1\bob\applic~1\Qupim
    2011-04-06 17:33:43 -------- d-----w- c:\docume~1\bob\applic~1\Azawoq
    2011-04-06 13:29:32 -------- d-----w- c:\docume~1\bob\applic~1\ynafzasdaxazdvquptrju3hcert2xtb2
    2011-04-04 17:33:25 -------- d-----w- c:\windows\system32\wbem\repository\FS
    2011-04-04 17:33:25 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-03-30 22:17:22 134480 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
    2011-03-30 13:15:38 -------- d-----w- c:\docume~1\alluse~1\applic~1\iMg28604kIaGl28604
    .
    ==================== Find3M ====================
    .
    2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-07 02:08:13 93552 ----a-w- c:\windows\system32\ElbyCDIO.dll
    2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:06:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 11:41:59 385024 ----a-w- c:\windows\system32\html.iec
    2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
    2011-02-11 13:25:52 229888 ----a-w- c:\windows\system32\fxscover.exe
    2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
    2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
    2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
    2009-10-03 16:43:23 8410624 ----a-w- c:\program files\HTML Guardian 7.msi
    .
    ============= FINISH: 7:32:44.29 ===============


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Right Media: Tracking cookie (Internet Explorer: Bob) (Cookie, nothing done)



    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-04-27 RootAlyzer.exe (0.3.4.47)
    2008-01-28 SDDelFile.exe (1.0.2.4)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDShred.exe (1.0.2.5)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2008-08-14 SDWinSec.exe (1.0.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-02-11 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-11-04 advcheck.dll (1.6.5.20)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2011-03-18 Includes\Adware.sbi (*)
    2011-03-22 Includes\AdwareC.sbi (*)
    2010-08-13 Includes\Cookies.sbi (*)
    2010-12-14 Includes\Dialer.sbi (*)
    2011-03-08 Includes\DialerC.sbi (*)
    2011-02-24 Includes\HeavyDuty.sbi (*)
    2011-03-29 Includes\Hijackers.sbi (*)
    2011-03-29 Includes\HijackersC.sbi (*)
    2010-09-15 Includes\iPhone.sbi (*)
    2010-12-14 Includes\Keyloggers.sbi (*)
    2011-03-08 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2011-04-05 Includes\Malware.sbi (*)
    2011-04-19 Includes\MalwareC.sbi (*)
    2011-02-24 Includes\PUPS.sbi (*)
    2011-03-15 Includes\PUPSC.sbi (*)
    2010-01-25 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2011-03-08 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2011-02-24 Includes\Spyware.sbi (*)
    2011-03-15 Includes\SpywareC.sbi (*)
    2010-03-08 Includes\Tracks.uti
    2010-12-28 Includes\Trojans.sbi (*)
    2011-04-20 Includes\TrojansC-02.sbi (*)
    2011-04-18 Includes\TrojansC-03.sbi (*)
    2011-04-18 Includes\TrojansC-04.sbi (*)
    2011-04-11 Includes\TrojansC-05.sbi (*)
    2011-03-08 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    Please do NOT run 'FIXES' (ComboFix etc) without being asked

    Post back contents of already existing c:\ComboFix.txt file there.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Member
    Join Date
    Apr 2011
    Posts
    78

    Default

    That combo fix file was actually created before the last batch of problems starting showing up. I attempted to fix it myself - probably not a smart thing to do.

    The new batch of problems that I'm having seem to be different than the ones I had before.

    Can we just start from scratch as if I had not attempted any fixes yet?

  4. #4
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    I need to see that older log to find out what has been removed there earlier.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #5
    Member
    Join Date
    Apr 2011
    Posts
    78

    Default

    OK - Here ya go. I won't try anything else unless instructed by you.

    Thank you.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    ComboFix 11-04-10.01 - Bob 04/10/2011 14:52:29.10.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1413 [GMT -5:00]
    Running from: c:\documents and settings\Bob\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Bob\Desktop\CFScript.txt
    AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\\Documents and Settings\\Bob\\Application Data\\ynafzasdaxazdvquptrju3hcert2xtb2\csrss.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-03-10 to 2011-04-10 )))))))))))))))))))))))))))))))
    .
    .
    2011-04-09 22:00 . 2011-04-09 22:00 -------- d-----w- c:\documents and settings\Bob\Application Data\AVG9
    2011-04-09 15:12 . 2011-04-09 18:33 -------- d-----w- c:\documents and settings\All Users\Application Data\bBe14005kFaLe14005
    2011-04-06 19:43 . 2011-04-10 11:32 -------- d-----w- C:\wkep
    2011-04-06 19:37 . 2011-04-06 19:37 -------- d-----w- C:\My Lockbox
    2011-04-06 19:37 . 2010-07-22 21:13 41912 ----a-w- c:\windows\system32\drivers\FSPFltd.sys
    2011-04-06 17:33 . 2011-04-09 21:23 -------- d-----w- c:\documents and settings\Bob\Application Data\Azawoq
    2011-04-06 17:33 . 2011-04-07 11:01 -------- d-----w- c:\documents and settings\Bob\Application Data\Qupim
    2011-04-06 13:29 . 2011-04-10 20:00 -------- d-----w- c:\documents and settings\Bob\Application Data\ynafzasdaxazdvquptrju3hcert2xtb2
    2011-04-04 17:33 . 2011-04-04 17:33 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-03-30 13:30 . 2011-03-30 13:33 -------- d-----w- c:\documents and settings\Administrator.INSPIRON\Application Data\vlc
    2011-03-30 13:15 . 2011-03-30 13:33 -------- d-----w- c:\documents and settings\All Users\Application Data\iMg28604kIaGl28604
    2011-03-16 21:21 . 2011-03-16 21:21 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\CliSecure
    2011-03-16 16:31 . 2011-03-16 21:20 -------- d-----w- c:\program files\SecureTeam
    2011-03-14 15:01 . 2011-03-14 15:01 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-07 02:08 . 2011-03-07 02:08 93552 ----a-w- c:\windows\system32\ElbyCDIO.dll
    2011-02-09 13:53 . 2004-08-04 10:00 270848 ----a-w- c:\windows\system32\sbe.dll
    2011-02-09 13:53 . 2004-08-04 10:00 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-02-04 21:09 . 2011-02-04 21:09 4640 ----a-w- c:\windows\system32\yZkSy3.0
    2011-02-02 07:58 . 2008-01-13 03:19 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2011-01-27 11:57 . 2008-01-13 03:19 677888 ----a-w- c:\windows\system32\mstsc.exe
    2011-01-21 14:44 . 2004-08-04 10:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2009-10-03 16:43 . 2009-10-03 16:43 8410624 ----a-w- c:\program files\HTML Guardian 7.msi
    2009-08-20 23:58 . 2009-08-20 23:58 27976 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
    2009-08-20 23:58 . 2009-08-20 23:58 126360 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
    2009-08-20 23:58 . 2009-08-20 23:58 98712 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-04-10_15.35.57 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2011-04-10 15:41 . 2011-04-10 15:41 16384 c:\windows\temp\Perflib_Perfdata_cac.dat
    + 2011-04-10 15:40 . 2011-04-10 15:40 16384 c:\windows\temp\Perflib_Perfdata_748.dat
    + 2011-04-10 15:40 . 2011-04-10 15:40 16384 c:\windows\temp\Perflib_Perfdata_21c.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2011-03-07 4886136]
    "Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-02-22 2272592]
    "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-03-09 26103592]
    "OpenDNS Updater"="c:\program files\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
    "0EBC39E44532BFFB"="c:\upsd\upsd.exe" [2011-04-10 143360]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
    "EPSON Stylus CX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE" [2005-02-07 98304]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
    "AdobeVersionCue"="c:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe" [2003-10-13 1732608]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
    "RTHDCPL"="RTHDCPL.EXE" [2008-02-05 16859648]
    "Norton Ghost 14.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2008-01-20 2245984]
    "ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2005-02-16 221184]
    "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-01-27 63048]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "mylbx"="c:\program files\My Lockbox\mylbx.exe" [2011-03-27 1900864]
    .
    c:\documents and settings\Bob\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
    Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1996-11-17 111376]
    Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1996-11-17 51984]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Acrobat Assistant.lnk - c:\program files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 217194]
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-1-24 110592]
    Omega Research Task Scheduler.lnk - c:\program files\Omega Research\Program\orschd.exe [2008-3-19 148480]
    PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [N/A]
    Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
    2010-12-08 19:11 87424 ----a-w- c:\windows\system32\LMIinit.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "mixer"=DrvTrNTm.dll
    "wave"=DrvTrNTm.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
    "c:\\WINDOWS\\system32\\dpvsetup.exe"=
    "c:\\Program Files\\1stWORKS\\hotCommCL\\BIN\\HotComm.exe"=
    "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\WINDOWS\\system32\\hkcmd.exe"=
    "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
    "c:\\Program Files\\NinjaTrader 7\\bin\\NinjaTrader.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
    "2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)
    .
    R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [4/6/2011 2:37 PM 41912]
    R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
    R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [10/5/2010 7:39 PM 374152]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/27/2010 12:22 PM 12856]
    R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/4/2004 5:00 AM 5120]
    R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [12/20/2007 5:13 PM 1553896]
    R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [5/10/2009 4:26 PM 127496]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
    S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys --> c:\windows\system32\DRIVERS\nlndis.sys [?]
    S3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys --> c:\windows\system32\DRIVERS\nlndis.sys [?]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-04-10 c:\windows\Tasks\User_Feed_Synchronization-{1FF685FF-AF79-4E0B-A492-555956BF9C7C}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://twitter.com/
    uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=%s
    DPF: {254AA86E-5655-4518-AA87-185D7CC41801} - hxxps://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
    FF - ProfilePath - c:\documents and settings\Bob\Application Data\Mozilla\Firefox\Profiles\vw9a9lod.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
    FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
    FF - Ext: Echofon: twitternotifier@naan.net - %profile%\extensions\twitternotifier@naan.net
    FF - Ext: PDF Download: {37E4D8EA-8BDA-4831-8EA1-89053939A250} - %profile%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
    FF - Ext: Ant Video Downloader: anttoolbar@ant.com - %profile%\extensions\anttoolbar@ant.com
    FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
    FF - user.js: capability.policy.policynames - allowclipboard
    FF - user.js: capability.policy.allowclipboard.sites - hxxp://www.insidefutures.com http://www.futuresknowledge.com
    FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
    FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-04-10 15:00
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    0EBC39E44532BFFB = c:\upsd\upsd.exe
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(752)
    c:\windows\system32\LMIinit.dll
    c:\windows\system32\LMIRfsClientNP.dll
    c:\windows\system32\WININET.dll
    .
    - - - - - - - > 'lsass.exe'(816)
    c:\windows\system32\WININET.dll
    .
    - - - - - - - > 'explorer.exe'(1628)
    c:\windows\system32\WININET.dll
    c:\program files\SlySoft\AnyDVD\ADvdDiscHlp1.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2011-04-10 15:02:50
    ComboFix-quarantined-files.txt 2011-04-10 20:02
    ComboFix2.txt 2011-04-10 15:37
    .
    Pre-Run: 44,581,068,800 bytes free
    Post-Run: 44,552,003,584 bytes free
    .
    - - End Of File - - B96CD00D4A09934BFF6BD2C7DA52041A

  6. #6
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Please re-run ComboFix and let it update itself. Post back the log + fresh dds logs.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #7
    Member
    Join Date
    Apr 2011
    Posts
    78

    Default

    Here ya go.

    Thank you for your help.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    ComboFix 11-04-27.03 - Bob 04/28/2011 6:08.11.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1473 [GMT -5:00]
    Running from: c:\documents and settings\Bob\Desktop\ComboFix.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\All Users\Documents\dll
    c:\documents and settings\Bob\g2mdlhlpx.exe
    c:\program files\Hotspot Shield\HssIE\HsSIe.dll
    c:\windows\system32\init32.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-03-28 to 2011-04-28 )))))))))))))))))))))))))))))))
    .
    .
    2011-04-26 23:40 . 2011-04-26 23:40 -------- d-----w- c:\documents and settings\Bob\Application Data\ApexFutures
    2011-04-26 23:39 . 2011-04-26 23:39 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\OEC
    2011-04-26 23:39 . 2011-04-26 23:39 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\ApexFutures
    2011-04-26 23:39 . 2011-04-26 23:39 -------- d-----w- c:\program files\OEC
    2011-04-26 23:39 . 2011-04-26 23:39 -------- d-----w- c:\program files\ApexTrader
    2011-04-26 19:55 . 2011-04-26 19:55 -------- d-----w- c:\documents and settings\All Users\Application Data\hssff
    2011-04-26 15:18 . 2011-04-26 15:18 -------- d-----w- C:\Hotspot Shield
    2011-04-26 15:17 . 2010-11-04 18:43 506880 ----a-w- c:\program files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor.dll
    2011-04-26 15:17 . 2011-04-26 15:17 -------- d-----w- c:\program files\Hotspot Shield
    2011-04-26 15:16 . 2011-04-26 15:15 270800 ----a-w- C:\DM-76.exe
    2011-04-18 12:18 . 2011-04-18 12:18 -------- d-----w- c:\documents and settings\All Users\Application Data\aAe06511eMbCp06511
    2011-04-14 14:56 . 2011-04-14 14:57 -------- d-----w- c:\documents and settings\All Users\Application Data\jPm06504jIdHj06504
    2011-04-12 17:13 . 2011-04-12 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\gJm06511lGnOa06511
    2011-04-12 16:28 . 2011-04-12 23:44 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\CRLCommonVdm
    2011-04-12 11:10 . 2011-04-12 11:10 -------- d-----w- c:\documents and settings\Bob\Application Data\IObit
    2011-04-11 21:02 . 2011-04-11 21:02 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Application Updater
    2011-04-11 12:57 . 2011-04-11 12:57 -------- d-----w- c:\documents and settings\Bob\Application Data\AVG10
    2011-04-11 12:23 . 2011-04-11 17:00 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
    2011-04-11 12:05 . 2011-04-11 12:06 -------- d-----w- c:\documents and settings\zxcasdqwe
    2011-04-11 10:40 . 2011-04-11 10:40 -------- d-----w- c:\program files\ESET
    2011-04-10 21:40 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-04-10 21:40 . 2011-04-10 21:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-04-10 21:40 . 2010-12-20 23:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-04-09 22:00 . 2011-04-09 22:00 -------- d-----w- c:\documents and settings\Bob\Application Data\AVG9
    2011-04-09 15:12 . 2011-04-09 18:33 -------- d-----w- c:\documents and settings\All Users\Application Data\bBe14005kFaLe14005
    2011-04-06 19:43 . 2011-04-27 11:09 -------- d-----w- C:\wkep
    2011-04-06 19:37 . 2011-04-06 19:37 -------- d-----w- C:\My Lockbox
    2011-04-06 19:37 . 2010-07-22 21:13 41912 ----a-w- c:\windows\system32\drivers\FSPFltd.sys
    2011-04-06 17:33 . 2011-04-09 21:23 -------- d-----w- c:\documents and settings\Bob\Application Data\Azawoq
    2011-04-06 17:33 . 2011-04-07 11:01 -------- d-----w- c:\documents and settings\Bob\Application Data\Qupim
    2011-04-06 13:29 . 2011-04-10 20:00 -------- d-----w- c:\documents and settings\Bob\Application Data\ynafzasdaxazdvquptrju3hcert2xtb2
    2011-04-04 17:33 . 2011-04-04 17:33 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-03-30 13:30 . 2011-03-30 13:33 -------- d-----w- c:\documents and settings\Administrator.INSPIRON\Application Data\vlc
    2011-03-30 13:15 . 2011-03-30 13:33 -------- d-----w- c:\documents and settings\All Users\Application Data\iMg28604kIaGl28604
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-07 05:33 . 2008-01-13 03:20 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-07 02:08 . 2011-03-07 02:08 93552 ----a-w- c:\windows\system32\ElbyCDIO.dll
    2011-03-04 06:37 . 2004-08-04 10:00 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:21 . 2004-08-04 10:00 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:06 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:06 . 2004-08-04 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:06 . 2004-08-04 10:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 11:41 . 2004-08-04 10:00 385024 ----a-w- c:\windows\system32\html.iec
    2011-02-17 13:18 . 2004-08-04 10:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-02-17 13:18 . 2004-08-04 10:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys
    2011-02-17 12:32 . 2009-04-16 16:36 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2011-02-15 12:56 . 2004-08-04 10:00 290432 ----a-w- c:\windows\system32\atmfd.dll
    2011-02-11 13:25 . 2008-05-15 12:38 229888 ----a-w- c:\windows\system32\fxscover.exe
    2011-02-09 13:53 . 2004-08-04 10:00 270848 ----a-w- c:\windows\system32\sbe.dll
    2011-02-09 13:53 . 2004-08-04 10:00 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-02-08 13:33 . 2004-08-04 10:00 978944 ----a-w- c:\windows\system32\mfc42.dll
    2011-02-08 13:33 . 2004-08-04 10:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2011-02-02 07:58 . 2008-01-13 03:19 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2009-10-03 16:43 . 2009-10-03 16:43 8410624 ----a-w- c:\program files\HTML Guardian 7.msi
    2009-08-20 23:58 . 2009-08-20 23:58 27976 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
    2009-08-20 23:58 . 2009-08-20 23:58 126360 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
    2009-08-20 23:58 . 2009-08-20 23:58 98712 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-04-10_15.35.57 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-07-12 05:02 . 2009-07-12 05:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
    + 2009-07-12 05:05 . 2009-07-12 05:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
    + 2009-07-12 05:05 . 2009-07-12 05:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
    + 2011-04-28 11:03 . 2011-04-28 11:03 16384 c:\windows\temp\Perflib_Perfdata_e38.dat
    + 2011-04-28 11:03 . 2011-04-28 11:03 16384 c:\windows\temp\Perflib_Perfdata_860.dat
    + 2011-04-28 11:02 . 2011-04-28 11:02 16384 c:\windows\temp\Perflib_Perfdata_7d0.dat
    - 2006-03-04 03:33 . 2010-12-20 23:59 66560 c:\windows\system32\mshtmled.dll
    + 2006-03-04 03:33 . 2011-02-22 23:06 66560 c:\windows\system32\mshtmled.dll
    - 2009-03-08 09:31 . 2010-12-20 23:59 55296 c:\windows\system32\msfeedsbs.dll
    + 2009-03-08 09:31 . 2011-02-22 23:06 55296 c:\windows\system32\msfeedsbs.dll
    + 2004-08-04 10:00 . 2011-02-22 23:06 25600 c:\windows\system32\jsproxy.dll
    - 2004-08-04 10:00 . 2010-12-20 23:59 25600 c:\windows\system32\jsproxy.dll
    - 2004-08-04 10:00 . 2008-04-14 00:11 45568 c:\windows\system32\dnsrslvr.dll
    + 2004-08-04 10:00 . 2009-04-20 17:17 45568 c:\windows\system32\dnsrslvr.dll
    - 2009-09-16 16:37 . 2010-12-20 23:59 12800 c:\windows\system32\dllcache\xpshims.dll
    + 2009-09-16 16:37 . 2011-02-22 23:06 12800 c:\windows\system32\dllcache\xpshims.dll
    + 2006-03-04 03:33 . 2011-02-22 23:06 66560 c:\windows\system32\dllcache\mshtmled.dll
    - 2006-03-04 03:33 . 2010-12-20 23:59 66560 c:\windows\system32\dllcache\mshtmled.dll
    + 2009-09-16 16:37 . 2011-02-22 23:06 55296 c:\windows\system32\dllcache\msfeedsbs.dll
    - 2009-09-16 16:37 . 2010-12-20 23:59 55296 c:\windows\system32\dllcache\msfeedsbs.dll
    - 2004-08-04 10:00 . 2010-12-20 23:59 43520 c:\windows\system32\dllcache\licmgr10.dll
    + 2004-08-04 10:00 . 2011-02-22 23:06 43520 c:\windows\system32\dllcache\licmgr10.dll
    + 2009-03-08 09:33 . 2011-02-22 23:06 25600 c:\windows\system32\dllcache\jsproxy.dll
    - 2009-03-08 09:33 . 2010-12-20 23:59 25600 c:\windows\system32\dllcache\jsproxy.dll
    + 2009-04-20 17:17 . 2009-04-20 17:17 45568 c:\windows\system32\dllcache\dnsrslvr.dll
    + 2010-06-05 03:08 . 2011-04-22 02:51 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
    - 2010-06-05 03:08 . 2011-03-18 03:02 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 12800 c:\windows\ie8updates\KB2497640-IE8\xpshims.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 66560 c:\windows\ie8updates\KB2497640-IE8\mshtmled.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 55296 c:\windows\ie8updates\KB2497640-IE8\msfeedsbs.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 43520 c:\windows\ie8updates\KB2497640-IE8\licmgr10.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 25600 c:\windows\ie8updates\KB2497640-IE8\jsproxy.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\368187bcb570d202a019fc7c53b1df4c\UIAutomationProvider.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\3f621b90371e67197bd4d0b86aa6f21d\System.Windows.Presentation.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\577b049541803541e6b00e2c36c00852\System.Web.DynamicData.Design.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\636ed65b7e5481320e3010b78a5e6cfa\System.ComponentModel.DataAnnotations.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f83b1e8dd8c90490c8d924826c8b107d\System.AddIn.Contract.ni.dll
    + 2011-04-16 03:04 . 2011-04-16 03:04 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\2740ba673b1040f1995f13c6044da64c\PresentationFontCache.ni.exe
    + 2011-04-16 03:04 . 2011-04-16 03:04 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\8514e7de63d46b6f8232ef70d93a1650\PresentationCFFRasterizer.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\108426b4dc654100c9a99bfa71f69886\Microsoft.Vsa.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\8905268997c77a27c7f9c54aeba37f24\Microsoft.Build.Framework.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\11bb8ef375848eb1c074da1afd5cecdc\Microsoft.Build.Framework.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\6d74b9308a1517bfe959e597c3dd2427\dfsvc.ni.exe
    + 2011-04-16 11:24 . 2011-04-16 11:24 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\fdf7f1404f4a5c7f5a0463d8e7a442e4\Accessibility.ni.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2011-04-10 21:30 . 2011-04-10 21:30 9081 c:\windows\extend.dat
    + 2011-04-16 03:02 . 2011-04-16 03:02 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
    + 2009-07-12 05:05 . 2009-07-12 05:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
    - 2004-08-04 10:00 . 2011-03-13 12:49 585216 c:\windows\system32\perfh009.dat
    + 2004-08-04 10:00 . 2011-04-16 03:03 585216 c:\windows\system32\perfh009.dat
    - 2004-08-04 10:00 . 2011-03-13 12:49 121622 c:\windows\system32\perfc009.dat
    + 2004-08-04 10:00 . 2011-04-16 03:03 121622 c:\windows\system32\perfc009.dat
    + 2004-08-04 10:00 . 2011-02-22 23:06 206848 c:\windows\system32\occache.dll
    - 2004-08-04 10:00 . 2010-12-20 23:59 206848 c:\windows\system32\occache.dll
    - 2004-08-04 10:00 . 2008-06-20 17:46 245248 c:\windows\system32\mswsock.dll
    + 2004-08-04 10:00 . 2008-06-20 16:02 245248 c:\windows\system32\mswsock.dll
    + 2006-03-04 03:33 . 2011-02-22 23:06 611840 c:\windows\system32\mstime.dll
    - 2006-03-04 03:33 . 2010-12-20 23:59 611840 c:\windows\system32\mstime.dll
    - 2009-03-08 09:32 . 2010-12-20 23:59 602112 c:\windows\system32\msfeeds.dll
    + 2009-03-08 09:32 . 2011-02-22 23:06 602112 c:\windows\system32\msfeeds.dll
    + 2011-04-21 10:50 . 2011-04-21 10:50 235168 c:\windows\system32\Macromed\Flash\FlashUtil10p_Plugin.exe
    + 2004-08-04 10:00 . 2011-03-04 06:37 726528 c:\windows\system32\jscript.dll
    - 2004-08-04 10:00 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll
    + 2006-03-04 03:33 . 2011-02-22 23:06 184320 c:\windows\system32\iepeers.dll
    - 2006-03-04 03:33 . 2010-12-20 23:59 184320 c:\windows\system32\iepeers.dll
    + 2004-08-04 10:00 . 2011-02-22 23:06 387584 c:\windows\system32\iedkcs32.dll
    - 2004-08-04 10:00 . 2010-12-20 23:59 387584 c:\windows\system32\iedkcs32.dll
    + 2004-08-04 10:00 . 2011-02-18 11:49 173568 c:\windows\system32\ie4uinit.exe
    - 2004-08-04 10:00 . 2010-12-20 12:55 173568 c:\windows\system32\ie4uinit.exe
    - 2008-01-12 20:02 . 2011-02-10 12:01 199896 c:\windows\system32\FNTCACHE.DAT
    + 2008-01-12 20:02 . 2011-04-16 10:44 199896 c:\windows\system32\FNTCACHE.DAT
    - 2004-08-04 10:00 . 2008-08-14 10:04 138496 c:\windows\system32\drivers\afd.sys
    + 2004-08-04 10:00 . 2008-10-16 14:43 138496 c:\windows\system32\drivers\afd.sys
    + 2004-08-04 10:00 . 2011-03-03 06:55 149504 c:\windows\system32\dnsapi.dll
    + 2009-02-20 08:10 . 2011-02-22 23:06 916480 c:\windows\system32\dllcache\wininet.dll
    - 2009-02-20 08:10 . 2010-12-20 23:59 916480 c:\windows\system32\dllcache\wininet.dll
    + 2008-05-09 10:53 . 2011-03-04 06:37 420864 c:\windows\system32\dllcache\vbscript.dll
    + 2004-08-04 10:00 . 2011-02-17 13:18 357888 c:\windows\system32\dllcache\srv.sys
    - 2009-03-08 09:34 . 2010-12-20 23:59 206848 c:\windows\system32\dllcache\occache.dll
    + 2009-03-08 09:34 . 2011-02-22 23:06 206848 c:\windows\system32\dllcache\occache.dll
    + 2008-06-20 17:46 . 2008-06-20 16:02 245248 c:\windows\system32\dllcache\mswsock.dll
    - 2008-06-20 17:46 . 2008-06-20 17:46 245248 c:\windows\system32\dllcache\mswsock.dll
    - 2006-03-04 03:33 . 2010-12-20 23:59 611840 c:\windows\system32\dllcache\mstime.dll
    + 2006-03-04 03:33 . 2011-02-22 23:06 611840 c:\windows\system32\dllcache\mstime.dll
    + 2009-09-16 16:37 . 2011-02-22 23:06 602112 c:\windows\system32\dllcache\msfeeds.dll
    - 2009-09-16 16:37 . 2010-12-20 23:59 602112 c:\windows\system32\dllcache\msfeeds.dll
    + 2004-08-04 10:00 . 2011-02-17 13:18 455936 c:\windows\system32\dllcache\mrxsmb.sys
    + 2004-08-04 10:00 . 2011-02-08 13:33 974848 c:\windows\system32\dllcache\mfc42u.dll
    - 2004-08-04 10:00 . 2010-09-18 17:23 974848 c:\windows\system32\dllcache\mfc42u.dll
    + 2010-10-13 10:53 . 2011-02-08 13:33 978944 c:\windows\system32\dllcache\mfc42.dll
    + 2008-05-09 10:53 . 2011-03-04 06:37 726528 c:\windows\system32\dllcache\jscript.dll
    - 2008-05-09 10:53 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
    - 2009-05-02 18:21 . 2010-06-09 07:43 692736 c:\windows\system32\dllcache\inetcomm.dll
    + 2009-05-02 18:21 . 2011-03-07 05:33 692736 c:\windows\system32\dllcache\inetcomm.dll
    - 2009-09-16 16:37 . 2010-12-20 23:59 247808 c:\windows\system32\dllcache\ieproxy.dll
    + 2009-09-16 16:37 . 2011-02-22 23:06 247808 c:\windows\system32\dllcache\ieproxy.dll
    + 2009-03-08 09:31 . 2011-02-22 23:06 184320 c:\windows\system32\dllcache\iepeers.dll
    - 2009-03-08 09:31 . 2010-12-20 23:59 184320 c:\windows\system32\dllcache\iepeers.dll
    - 2010-06-09 11:17 . 2010-12-20 23:59 743424 c:\windows\system32\dllcache\iedvtool.dll
    + 2010-06-09 11:17 . 2011-02-22 23:06 743424 c:\windows\system32\dllcache\iedvtool.dll
    - 2009-03-08 19:09 . 2010-12-20 23:59 387584 c:\windows\system32\dllcache\iedkcs32.dll
    + 2009-03-08 19:09 . 2011-02-22 23:06 387584 c:\windows\system32\dllcache\iedkcs32.dll
    - 2009-03-08 09:32 . 2010-12-20 12:55 173568 c:\windows\system32\dllcache\ie4uinit.exe
    + 2009-03-08 09:32 . 2011-02-18 11:49 173568 c:\windows\system32\dllcache\ie4uinit.exe
    + 2008-05-15 12:38 . 2011-02-11 13:25 229888 c:\windows\system32\dllcache\fxscover.exe
    + 2008-06-20 17:46 . 2011-03-03 06:55 149504 c:\windows\system32\dllcache\dnsapi.dll
    + 2004-08-04 10:00 . 2008-04-14 00:11 640000 c:\windows\system32\dllcache\dbghelp.dll
    + 2010-04-20 05:30 . 2011-02-15 12:56 290432 c:\windows\system32\dllcache\atmfd.dll
    + 2004-08-04 10:00 . 2008-10-16 14:43 138496 c:\windows\system32\dllcache\afd.sys
    - 2004-08-04 10:00 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
    + 2011-02-11 13:25 . 2011-02-11 13:25 229888 c:\windows\ServicePackFiles\ServicePackCache\i386\fxscover.exe
    - 2010-05-11 11:40 . 2010-05-11 11:40 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    + 2011-01-18 09:39 . 2011-01-18 09:39 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    + 2011-01-18 09:39 . 2011-01-18 09:39 363856 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
    - 2010-05-11 11:40 . 2010-05-11 11:40 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    + 2011-01-18 09:39 . 2011-01-18 09:39 989016 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    + 2011-04-11 12:54 . 2011-04-11 12:54 219648 c:\windows\Installer\836b23.msi
    + 2011-04-16 02:58 . 2010-03-10 06:15 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
    + 2011-04-16 02:58 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
    + 2011-04-16 02:58 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
    + 2011-04-16 02:58 . 2009-12-09 05:53 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 916480 c:\windows\ie8updates\KB2497640-IE8\wininet.dll
    + 2011-04-16 03:03 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2497640-IE8\spuninst\updspapi.dll
    + 2011-04-16 03:03 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2497640-IE8\spuninst\spuninst.exe
    + 2011-04-16 03:03 . 2010-12-20 23:59 206848 c:\windows\ie8updates\KB2497640-IE8\occache.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 611840 c:\windows\ie8updates\KB2497640-IE8\mstime.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 602112 c:\windows\ie8updates\KB2497640-IE8\msfeeds.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 247808 c:\windows\ie8updates\KB2497640-IE8\ieproxy.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 184320 c:\windows\ie8updates\KB2497640-IE8\iepeers.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 743424 c:\windows\ie8updates\KB2497640-IE8\iedvtool.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 387584 c:\windows\ie8updates\KB2497640-IE8\iedkcs32.dll
    + 2011-04-16 03:03 . 2010-12-20 12:55 173568 c:\windows\ie8updates\KB2497640-IE8\ie4uinit.exe
    + 2011-04-28 10:36 . 2011-04-28 10:36 348160 c:\windows\ERDNT\AutoBackup\4-28-2011\Users\00000002\UsrClass.dat
    + 2011-04-28 10:36 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-28-2011\ERDNT.EXE
    + 2011-04-27 10:41 . 2011-04-27 10:41 348160 c:\windows\ERDNT\AutoBackup\4-27-2011\Users\00000002\UsrClass.dat
    + 2011-04-27 10:41 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-27-2011\ERDNT.EXE
    + 2011-04-26 10:55 . 2011-04-26 10:55 348160 c:\windows\ERDNT\AutoBackup\4-26-2011\Users\00000002\UsrClass.dat
    + 2011-04-26 10:55 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-26-2011\ERDNT.EXE
    + 2011-04-25 10:50 . 2011-04-25 10:50 348160 c:\windows\ERDNT\AutoBackup\4-25-2011\Users\00000002\UsrClass.dat
    + 2011-04-25 10:50 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-25-2011\ERDNT.EXE
    + 2011-04-24 11:13 . 2011-04-24 11:13 348160 c:\windows\ERDNT\AutoBackup\4-24-2011\Users\00000002\UsrClass.dat
    + 2011-04-24 11:13 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-24-2011\ERDNT.EXE
    + 2011-04-23 10:47 . 2011-04-23 10:47 348160 c:\windows\ERDNT\AutoBackup\4-23-2011\Users\00000002\UsrClass.dat
    + 2011-04-23 10:47 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-23-2011\ERDNT.EXE
    + 2011-04-22 11:14 . 2011-04-22 11:14 348160 c:\windows\ERDNT\AutoBackup\4-22-2011\Users\00000002\UsrClass.dat
    + 2011-04-22 11:14 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-22-2011\ERDNT.EXE
    + 2011-04-21 10:48 . 2011-04-21 10:48 348160 c:\windows\ERDNT\AutoBackup\4-21-2011\Users\00000002\UsrClass.dat
    + 2011-04-21 10:48 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-21-2011\ERDNT.EXE
    + 2011-04-20 10:05 . 2011-04-20 10:05 348160 c:\windows\ERDNT\AutoBackup\4-20-2011\Users\00000002\UsrClass.dat
    + 2011-04-20 10:05 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-20-2011\ERDNT.EXE
    + 2011-04-19 10:48 . 2011-04-19 10:48 348160 c:\windows\ERDNT\AutoBackup\4-19-2011\Users\00000002\UsrClass.dat
    + 2011-04-19 10:48 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-19-2011\ERDNT.EXE
    + 2011-04-18 10:30 . 2011-04-18 10:30 348160 c:\windows\ERDNT\AutoBackup\4-18-2011\Users\00000002\UsrClass.dat
    + 2011-04-18 10:30 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-18-2011\ERDNT.EXE
    + 2011-04-17 11:44 . 2011-04-17 11:44 348160 c:\windows\ERDNT\AutoBackup\4-17-2011\Users\00000002\UsrClass.dat
    + 2011-04-17 11:44 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-17-2011\ERDNT.EXE
    + 2011-04-16 10:44 . 2011-04-16 10:44 348160 c:\windows\ERDNT\AutoBackup\4-16-2011\Users\00000002\UsrClass.dat
    + 2011-04-16 10:44 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-16-2011\ERDNT.EXE
    + 2011-04-15 10:22 . 2011-04-15 10:22 348160 c:\windows\ERDNT\AutoBackup\4-15-2011\Users\00000002\UsrClass.dat
    + 2011-04-15 10:22 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-15-2011\ERDNT.EXE
    + 2011-04-14 10:46 . 2011-04-14 10:46 348160 c:\windows\ERDNT\AutoBackup\4-14-2011\Users\00000002\UsrClass.dat
    + 2011-04-14 10:47 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-14-2011\ERDNT.EXE
    + 2011-04-13 10:42 . 2011-04-13 10:42 348160 c:\windows\ERDNT\AutoBackup\4-13-2011\Users\00000002\UsrClass.dat
    + 2011-04-13 10:42 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-13-2011\ERDNT.EXE
    + 2011-04-12 11:10 . 2011-04-12 11:10 348160 c:\windows\ERDNT\AutoBackup\4-12-2011\Users\00000002\UsrClass.dat
    + 2011-04-12 11:10 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-12-2011\ERDNT.EXE
    + 2011-04-11 10:32 . 2011-04-11 10:32 348160 c:\windows\ERDNT\AutoBackup\4-11-2011\Users\00000002\UsrClass.dat
    + 2011-04-11 10:32 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-11-2011\ERDNT.EXE
    + 2009-05-02 18:27 . 2011-02-17 13:18 455936 c:\windows\Driver Cache\i386\mrxsmb.sys
    + 2011-04-16 11:24 . 2011-04-16 11:24 321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\95de80b860252231b46014f58226e473\WsatConfig.ni.exe
    + 2011-04-16 10:46 . 2011-04-16 10:46 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\715710f5a31a494ed5c0ec0874dafe3e\WindowsFormsIntegration.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\017be0e6c5f1810f15a696157cd5e2c2\UIAutomationTypes.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\bec5b0a93df12eb26c02c877a4eae678\UIAutomationClient.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\3d8f787002439f4942c33f376cfd8555\System.Xml.Linq.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\4b746fea8062a10ccc6e5331914e7dad\System.Web.Routing.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\103956fdb019bce8a173fe9cb9da3e02\System.Web.RegularExpressions.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\c0a156fbf46ad272ac262e45eaa998f4\System.Web.Extensions.Design.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\e3651e13567ce4e3fa7bb2fbab737d9a\System.Web.Entity.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\834d7769f39e4d937eda1ad3707d4716\System.Web.Entity.Design.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\032c96c6206b53bca122d1fbaf5f8ca2\System.Web.DynamicData.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\6ce0e4fb33afcfcce43c427e82b987db\System.Web.Abstractions.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\990d96810a21e0fa95f916ffc66f3a94\System.Transactions.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e0d56c0582316e9ecb4c18186e37217c\System.ServiceProcess.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\9e91cca51a5ed6fb13b67558109d2726\System.Security.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\fa6a58394a1f162eecce4cd8af0875c3\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\6194eb4bc1e0133d0183d086b747f512\System.Net.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\042658de519bb1e22ec5925092061892\System.Management.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\d6ae8171ae6fd4fe83add34e6d70e5b5\System.Management.Instrumentation.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\abd5a61d39e474f12b30ccbbe6277667\System.IO.Log.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\12c4dba6d4ff0278d208c283d9ed7670\System.IdentityModel.Selectors.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\ff5c7a52497d892f3a3206384d46b5e7\System.EnterpriseServices.Wrapper.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\ff5c7a52497d892f3a3206384d46b5e7\System.EnterpriseServices.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\e6b7128278d8c0e8382a5685f5b196c6\System.Drawing.Design.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\8ef56bf47fc2fc4204e0fcc1f32bab01\System.DirectoryServices.AccountManagement.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\447d7b4a7d0add13f8d2086088bcc41c\System.DirectoryServices.Protocols.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\ce2afe8854ee9cdc834b6f392348c882\System.Data.Services.Design.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\03d4658290e300e437e745ef4a613b59\System.Data.Services.Client.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\7ce21a2855bb7731de4dab797e69f3f6\System.Data.Entity.Design.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\ea57694aea47c05853516c9bb2ad54b4\System.Data.DataSetExtensions.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d6b4509225efde2a4e3db77205f8a51\System.Configuration.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f312bb844670ebc7458fec9e6b2568b3\System.Configuration.Install.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\afd9595f07a8c68b26e81cf995957f56\System.AddIn.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\3a42b2fbafe93d7b9395e328bea35afa\SMSvcHost.ni.exe
    + 2011-04-16 11:24 . 2011-04-16 11:24 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\97ff96d3fc8d0b10ea294f320acf821e\SMDiagnostics.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\28ed0e9efd938b05b4f53e0d90046701\ServiceModelReg.ni.exe
    + 2011-04-16 10:46 . 2011-04-16 10:46 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ffe13679e6b3e36e5cb6c47f8c4faf9c\PresentationFramework.Aero.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\dbb40299379f2009c140ddadb04231b4\PresentationFramework.Classic.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a34cd33cec1bdfebe4a3910bceb8723b\PresentationFramework.Royale.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\689bb394bcb437ed085c22a43aba30c6\PresentationFramework.Luna.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\5670e74887ef1025c6a8c056ffe86b38\MSBuild.ni.exe
    + 2011-04-16 11:24 . 2011-04-16 11:24 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\653732002ebf5c68f69150a60e145e6a\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\cc62770393640302bd4d7e442b1e49a4\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\352bff1ee71ce114e225f849038dc48d\Microsoft.Build.Utilities.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\7345f4d2d7157bf49de4158e8f2b6847\Microsoft.Build.Engine.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\d7dba901ddd410ca1a0156d0f2a27533\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\010552e529d130ce914765b0801e2367\CustomMarshalers.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\6861f639b13967e9b014b44bbb7c5d4c\ComSvcConfig.ni.exe
    + 2011-04-16 11:24 . 2011-04-16 11:24 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\800da7dec567fadf3392091e9f01ecb9\AspNetMMCExt.ni.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2011-04-16 03:03 . 2011-04-16 03:03 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2011-04-16 03:03 . 2011-04-16 03:03 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    + 2011-04-15 10:25 . 2010-10-23 00:51 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
    + 2009-07-12 05:02 . 2009-07-12 05:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
    - 2006-03-18 11:09 . 2010-12-20 23:59 1210880 c:\windows\system32\urlmon.dll
    + 2006-03-18 11:09 . 2011-02-22 23:06 1210880 c:\windows\system32\urlmon.dll
    + 2006-03-23 17:32 . 2011-02-22 23:06 5962240 c:\windows\system32\mshtml.dll
    - 2010-01-27 01:07 . 2011-03-31 11:32 6053536 c:\windows\system32\Macromed\Flash\NPSWF32.dll
    + 2010-01-27 01:07 . 2011-04-21 10:50 6053536 c:\windows\system32\Macromed\Flash\NPSWF32.dll
    + 2007-08-13 23:34 . 2011-02-22 23:06 1991680 c:\windows\system32\iertutil.dll
    - 2007-08-13 23:34 . 2010-12-20 23:59 1991680 c:\windows\system32\iertutil.dll
    + 2009-02-09 11:13 . 2011-03-03 13:21 1857920 c:\windows\system32\dllcache\win32k.sys
    - 2009-02-20 08:10 . 2010-12-20 23:59 1210880 c:\windows\system32\dllcache\urlmon.dll
    + 2009-02-20 08:10 . 2011-02-22 23:06 1210880 c:\windows\system32\dllcache\urlmon.dll
    + 2009-02-20 08:11 . 2011-02-22 23:06 5962240 c:\windows\system32\dllcache\mshtml.dll
    + 2009-09-16 16:37 . 2011-02-22 23:06 1991680 c:\windows\system32\dllcache\iertutil.dll
    - 2009-09-16 16:37 . 2010-12-20 23:59 1991680 c:\windows\system32\dllcache\iertutil.dll
    + 2011-01-18 09:39 . 2011-01-18 09:39 5813072 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    - 2010-05-11 11:40 . 2010-05-11 11:40 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2011-01-18 09:39 . 2011-01-18 09:39 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 1210880 c:\windows\ie8updates\KB2497640-IE8\urlmon.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 5961216 c:\windows\ie8updates\KB2497640-IE8\mshtml.dll
    + 2011-04-16 03:03 . 2010-12-20 23:59 1991680 c:\windows\ie8updates\KB2497640-IE8\iertutil.dll
    + 2011-04-16 03:04 . 2011-04-16 03:04 3325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\76e431fde1b252312b331f7108259fda\WindowsBase.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\9e022c95e79f2b6f383a501ad99f08a9\UIAutomationClientsideProviders.ni.dll
    + 2011-04-16 03:04 . 2011-04-16 03:04 7949824 c:\windows\assembly\NativeImages_v2.0.50727_32\System\f02cf6430a9fc77908a74ab6925cb73c\System.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b06e49ed8cbe07dbb90e313fa634b27b\System.Xml.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\6346221cecf631e5c0b754d842aad102\System.WorkflowServices.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\1fbcd203ff8d77d561df8bf806417ab6\System.Workflow.Runtime.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\efbaf3696c44fd7d4b3cd925e0437b36\System.Workflow.ComponentModel.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\52a9bc5dd1fa497af7c7f4600bd8e6d1\System.Workflow.Activities.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\f5ebeeb0a8aaba9db15ec3df591339ba\System.Web.Services.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\92d6b75e3b63b528d4069bf4ee01983a\System.Web.Mobile.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 2405376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\02d53154634c8000382942e0f43ead41\System.Web.Extensions.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 1917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\dd128c8e21e7fa14c12b71df9892d046\System.Speech.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\8b0bb430bb6af96c18b43e3c54cfafe8\System.ServiceModel.Web.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 2345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\85090bd451617e204ffda625b8d9fc30\System.Runtime.Serialization.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\85a7a7aace114e78fc6c9b219bcd5551\System.Printing.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\d912066086a59f09424c7c69f95e2c55\System.Drawing.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c05d9332116964104c721e97f7ce1058\System.DirectoryServices.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\0118c0c73ea5c77bda7b10b188102ab6\System.Deployment.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 6616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\1337829e3df6888464a17aab78bb9b8f\System.Data.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\ba3ca7a93e227c32ce7b50d0a7ba935f\System.Data.SqlXml.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\2de52be5da96059651b5bec800cb4605\System.Data.Services.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 2516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\11f1306e0e311a0d0cbd139fb2fa4c36\System.Data.Linq.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\c91e83e85c030bc914ecc302fa9b2c60\System.Data.Entity.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 2295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\684fe21837d3cf3e5935bbd0a7f53141\System.Core.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 2128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\12efddabe6fe35be21246c88ed9bf8ab\ReachFramework.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\257c9327ba9cc5cd87f58de224aa2e0d\PresentationUI.ni.dll
    + 2011-04-16 03:04 . 2011-04-16 03:04 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b117bf63daa7e587f1bb2d975dccb4af\PresentationBuildTasks.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\269103939243ec6929739c8b9a645c0d\Microsoft.VisualBasic.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\bf7bd26d2828e35156814018939ce4f6\Microsoft.Transactions.Bridge.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\6594c17d7e112b0507b701d5b8a67bba\Microsoft.JScript.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\f5eb1e42ccd0f67f7496b94a31949cd0\Microsoft.Build.Tasks.ni.dll
    + 2011-04-16 11:25 . 2011-04-16 11:25 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\cc7f05675a5cd8014222be1483d6beaf\Microsoft.Build.Tasks.v3.5.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\41cf95aa4ff5765b515d3252abc6353b\Microsoft.Build.Engine.ni.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    + 2011-04-16 03:03 . 2011-04-16 03:03 3182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll


    CONTINUED NEXT POST

  8. #8
    Member
    Join Date
    Apr 2011
    Posts
    78

    Default

    COMBOFIX LOG CONTINUED



    - 2010-10-07 03:03 . 2010-10-07 03:03 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 5242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    + 2011-04-16 03:02 . 2011-04-16 03:02 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2010-10-07 03:03 . 2010-10-07 03:03 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2009-11-12 04:07 . 2011-04-18 20:46 42181064 c:\windows\system32\MRT.exe
    - 2007-08-13 23:54 . 2010-12-21 11:29 11080704 c:\windows\system32\ieframe.dll
    + 2007-08-13 23:54 . 2011-02-22 23:06 11080704 c:\windows\system32\ieframe.dll
    + 2009-09-16 16:37 . 2011-02-22 23:06 11080704 c:\windows\system32\dllcache\ieframe.dll
    - 2009-09-16 16:37 . 2010-12-21 11:29 11080704 c:\windows\system32\dllcache\ieframe.dll
    + 2011-02-12 01:47 . 2011-02-12 01:47 12028928 c:\windows\Installer\3937f19.msp
    + 2011-04-22 02:50 . 2011-04-22 02:50 20314624 c:\windows\Installer\372676b.msp
    + 2011-04-16 03:03 . 2010-12-21 11:29 11080704 c:\windows\ie8updates\KB2497640-IE8\ieframe.dll
    + 2011-04-28 10:36 . 2011-04-28 10:36 11808768 c:\windows\ERDNT\AutoBackup\4-28-2011\Users\00000001\ntuser.dat
    + 2011-04-27 10:41 . 2011-04-27 10:41 11808768 c:\windows\ERDNT\AutoBackup\4-27-2011\Users\00000001\ntuser.dat
    + 2011-04-26 10:55 . 2011-04-26 10:55 11808768 c:\windows\ERDNT\AutoBackup\4-26-2011\Users\00000001\ntuser.dat
    + 2011-04-25 10:50 . 2011-04-25 10:50 11808768 c:\windows\ERDNT\AutoBackup\4-25-2011\Users\00000001\ntuser.dat
    + 2011-04-24 11:13 . 2011-04-24 11:13 11808768 c:\windows\ERDNT\AutoBackup\4-24-2011\Users\00000001\ntuser.dat
    + 2011-04-23 10:47 . 2011-04-23 10:47 11808768 c:\windows\ERDNT\AutoBackup\4-23-2011\Users\00000001\ntuser.dat
    + 2011-04-22 11:14 . 2011-04-22 11:14 11808768 c:\windows\ERDNT\AutoBackup\4-22-2011\Users\00000001\ntuser.dat
    + 2011-04-21 10:48 . 2011-04-21 10:48 11808768 c:\windows\ERDNT\AutoBackup\4-21-2011\Users\00000001\ntuser.dat
    + 2011-04-20 10:05 . 2011-04-20 10:05 11808768 c:\windows\ERDNT\AutoBackup\4-20-2011\Users\00000001\ntuser.dat
    + 2011-04-19 10:48 . 2011-04-19 10:48 11808768 c:\windows\ERDNT\AutoBackup\4-19-2011\Users\00000001\ntuser.dat
    + 2011-04-18 10:30 . 2011-04-18 10:30 11808768 c:\windows\ERDNT\AutoBackup\4-18-2011\Users\00000001\ntuser.dat
    + 2011-04-17 11:44 . 2011-04-17 11:44 11808768 c:\windows\ERDNT\AutoBackup\4-17-2011\Users\00000001\ntuser.dat
    + 2011-04-16 10:44 . 2011-04-16 10:44 11808768 c:\windows\ERDNT\AutoBackup\4-16-2011\Users\00000001\ntuser.dat
    + 2011-04-15 10:22 . 2011-04-15 10:22 11808768 c:\windows\ERDNT\AutoBackup\4-15-2011\Users\00000001\ntuser.dat
    + 2011-04-14 10:46 . 2011-04-14 10:46 11808768 c:\windows\ERDNT\AutoBackup\4-14-2011\Users\00000001\ntuser.dat
    + 2011-04-13 10:42 . 2011-04-13 10:42 11808768 c:\windows\ERDNT\AutoBackup\4-13-2011\Users\00000001\ntuser.dat
    + 2011-04-12 11:10 . 2011-04-12 11:10 11808768 c:\windows\ERDNT\AutoBackup\4-12-2011\Users\00000001\ntuser.dat
    + 2011-04-11 10:32 . 2011-04-11 10:32 11808768 c:\windows\ERDNT\AutoBackup\4-11-2011\Users\00000001\ntuser.dat
    + 2011-04-16 10:46 . 2011-04-16 10:46 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ed2bf0d86229128c194a872f70fe15ee\System.Windows.Forms.ni.dll
    + 2011-04-16 11:26 . 2011-04-16 11:26 11800576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\d7b7ee04166212533ae21eaeb584fb0d\System.Web.ni.dll
    + 2011-04-16 11:24 . 2011-04-16 11:24 17403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\b5f24d96334ea08b99350421450d3ba4\System.ServiceModel.ni.dll
    + 2011-04-16 10:46 . 2011-04-16 10:46 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\5aeadb9ff9a86f49130de5976a9f1744\System.Design.ni.dll
    + 2011-04-16 10:45 . 2011-04-16 10:45 14328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1a5d89d569e2e12842daf4d87c57361a\PresentationFramework.ni.dll
    + 2011-04-16 03:04 . 2011-04-16 03:04 12215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\46c57d845e55232a89e98101075cd455\PresentationCore.ni.dll
    + 2011-04-16 03:03 . 2011-04-16 03:03 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62d5f089dd51f18472a7caf1593d9f6b\mscorlib.ni.dll
    .
    -- Snapshot reset to current date --
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2011-03-07 4886136]
    "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-03-09 26103592]
    "OpenDNS Updater"="c:\program files\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
    "EPSON Stylus CX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE" [2005-02-07 98304]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
    "AdobeVersionCue"="c:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe" [2003-10-13 1732608]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
    "RTHDCPL"="RTHDCPL.EXE" [2008-02-05 16859648]
    "Norton Ghost 14.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2008-01-20 2245984]
    "ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2005-02-16 221184]
    "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-01-27 63048]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "mylbx"="c:\program files\My Lockbox\mylbx.exe" [2011-03-27 1900864]
    .
    c:\documents and settings\Bob\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
    Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1996-11-17 111376]
    Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1996-11-17 51984]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Acrobat Assistant.lnk - c:\program files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 217194]
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-1-24 110592]
    Omega Research Task Scheduler.lnk - c:\program files\Omega Research\Program\orschd.exe [2008-3-19 148480]
    PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [N/A]
    Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
    2010-12-08 19:11 87424 ----a-w- c:\windows\system32\LMIinit.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "mixer"=DrvTrNTm.dll
    "wave"=DrvTrNTm.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
    "c:\\WINDOWS\\system32\\dpvsetup.exe"=
    "c:\\Program Files\\1stWORKS\\hotCommCL\\BIN\\HotComm.exe"=
    "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\WINDOWS\\system32\\hkcmd.exe"=
    "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
    "c:\\Program Files\\NinjaTrader 7\\bin\\NinjaTrader.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
    "2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)
    .
    R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [4/6/2011 2:37 PM 41912]
    R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
    R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [10/5/2010 7:39 PM 374152]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/27/2010 12:22 PM 12856]
    R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/4/2004 5:00 AM 5120]
    R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [12/20/2007 5:13 PM 1553896]
    R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [5/10/2009 4:26 PM 127496]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS --> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
    S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys --> c:\windows\system32\DRIVERS\nlndis.sys [?]
    S3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys --> c:\windows\system32\DRIVERS\nlndis.sys [?]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-04-27 c:\windows\Tasks\User_Feed_Synchronization-{1FF685FF-AF79-4E0B-A492-555956BF9C7C}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\program files\Common Files\Microsoft Shared\Stationery\Blank.htm
    uStart Page = hxxp://twitter.com/
    uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=%s
    FF - ProfilePath - c:\documents and settings\Bob\Application Data\Mozilla\Firefox\Profiles\vw9a9lod.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=685749&p=
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - Ext: afurladvisor: afurladvisor@anchorfree.com - c:\program files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com
    FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
    FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
    FF - Ext: Echofon: twitternotifier@naan.net - %profile%\extensions\twitternotifier@naan.net
    FF - Ext: PDF Download: {37E4D8EA-8BDA-4831-8EA1-89053939A250} - %profile%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
    FF - Ext: Ant Video Downloader: anttoolbar@ant.com - %profile%\extensions\anttoolbar@ant.com
    FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
    FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG10\Firefox4
    FF - user.js: capability.policy.policynames - allowclipboard
    FF - user.js: capability.policy.allowclipboard.sites - hxxp://www.insidefutures.com http://www.futuresknowledge.com
    FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
    FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-04-28 06:16
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(832)
    c:\windows\system32\LMIinit.dll
    c:\windows\system32\LMIRfsClientNP.dll
    .
    Completion time: 2011-04-28 06:18:10
    ComboFix-quarantined-files.txt 2011-04-28 11:17
    ComboFix2.txt 2011-04-10 20:02
    ComboFix3.txt 2011-04-10 15:37
    .
    Pre-Run: 84,114,743,296 bytes free
    Post-Run: 84,211,277,824 bytes free
    .
    - - End Of File - - 0ACD112D376F20A636F738D853A6165A


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Bob at 8:05:26.37 on Thu 04/28/2011
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1133 [GMT -5:00]
    .
    AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
    C:\WINDOWS\system32\svchost.exe -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\AVG\AVG10\avgwdsvc.exe
    C:\Program Files\Hotspot Shield\bin\hsswd.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\AVG\AVG10\avgnsx.exe
    C:\Program Files\AVG\AVG10\avgemcx.exe
    C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Norton Ghost\Agent\VProTray.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\My Lockbox\mylbx.exe
    C:\Program Files\AVG\AVG10\avgtray.exe
    C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
    C:\Program Files\DAEMON Tools Lite\DTLite.exe
    C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\Omega Research\Program\orschd.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\Norton Ghost\Agent\VProSvc.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
    C:\PROGRA~1\AVG\AVG10\avgrsx.exe
    C:\Program Files\AVG\AVG10\avgcsrvx.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\AVG\AVG10\avgcsrvx.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\Bob\Desktop\dds.scr
    .
    ============== Pseudo HJT Report ===============
    .
    uLocal Page = c:\program files\common files\microsoft shared\stationery\Blank.htm
    uStart Page = hxxp://twitter.com/
    uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=%s
    mURLSearchHooks: H - No File
    BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 7\SnagItBHO.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
    TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 7\SnagItIEAddin.dll
    TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
    TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
    uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe
    uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized
    uRun: [OpenDNS Updater] "c:\program files\opendns updater\OpenDNSUpdater.exe" /autostart
    uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [CloneCDTray] "c:\program files\slysoft\clonecd\CloneCDTray.exe" /s
    mRun: [EPSON Stylus CX3800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [AdobeVersionCue] c:\program files\adobe\adobe version cue\controlpanel\VersionCueTray.exe
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [Norton Ghost 14.0] "c:\program files\norton ghost\agent\VProTray.exe"
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
    mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [mylbx] c:\program files\my lockbox\mylbx.exe /a
    mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
    StartupFolder: c:\docume~1\bob\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\bob\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\FINDFAST.EXE
    StartupFolder: c:\docume~1\bob\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\adobe acrobat 6.0\distillr\acrotray.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\omegar~1.lnk - c:\program files\omega research\program\orschd.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\paltalk.lnk - c:\program files\paltalk messenger\paltalk.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - c:\program files\plotsoft\pdfill\DownloadPDF.exe
    IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {254AA86E-5655-4518-AA87-185D7CC41801} - hxxps://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
    Notify: igfxcui - igfxdev.dll
    Notify: LMIinit - LMIinit.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\docume~1\bob\applic~1\mozilla\firefox\profiles\vw9a9lod.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=685749&p=
    FF - component: c:\documents and settings\bob\application data\mozilla\firefox\profiles\vw9a9lod.default\extensions\dttoolbar@toolbarnet.com\components\DTToolbarFF.dll
    FF - component: c:\documents and settings\bob\application data\mozilla\firefox\profiles\vw9a9lod.default\extensions\twitternotifier@naan.net\platform\winnt\components\nsTwitterFoxSign.dll
    FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
    FF - component: c:\program files\mozilla firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor.dll
    FF - plugin: c:\documents and settings\bob\application data\mozilla\firefox\profiles\vw9a9lod.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\np32dsw.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\NPDOC.DLL
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npdrmv2.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npdsplay.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\NPJPI142_06.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nppdf32.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nppl3260.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nprfxins.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nprjplug.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nprpjplug.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\NPSVG3.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npwmsdrm.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npyacs.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - Ext: afurladvisor: afurladvisor@anchorfree.com - c:\program files\mozilla firefox\extensions\afurladvisor@anchorfree.com
    FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
    FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
    FF - Ext: Echofon: twitternotifier@naan.net - %profile%\extensions\twitternotifier@naan.net
    FF - Ext: PDF Download: {37E4D8EA-8BDA-4831-8EA1-89053939A250} - %profile%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
    FF - Ext: Ant Video Downloader: anttoolbar@ant.com - %profile%\extensions\anttoolbar@ant.com
    FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
    FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg10\Firefox4
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: capability.policy.policynames - allowclipboard
    FF - user.js: capability.policy.allowclipboard.sites - hxxp://www.insidefutures.com http://www.futuresknowledge.com
    FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
    FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32464]
    R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [2011-4-6 41912]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 296400]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-2-15 7421280]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
    R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
    R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2010-10-5 374152]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-1-27 12856]
    R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-7-13 47640]
    R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2004-8-4 5120]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134480]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216]
    R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2007-12-20 1553896]
    R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [2009-5-10 127496]
    S0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys --> c:\windows\system32\drivers\avgarkt.sys [?]
    S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
    S1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\avgarcln.sys --> c:\windows\system32\drivers\AvgArCln.sys [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" --> c:\program files\lavasoft\ad-aware\AAWService.exe [?]
    S3 NLNdisMP;NLNdisMP;c:\windows\system32\drivers\nlndis.sys --> c:\windows\system32\drivers\nlndis.sys [?]
    S3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\drivers\nlndis.sys --> c:\windows\system32\drivers\nlndis.sys [?]
    S4 LMIRfsClientNP;LMIRfsClientNP; [x]
    .
    =============== Created Last 30 ================
    .
    2011-04-28 11:30:28 -------- d-----w- c:\windows\system32\drivers\AVG
    2011-04-28 11:30:28 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVG10
    2011-04-26 23:40:11 -------- d-----w- c:\docume~1\bob\applic~1\ApexFutures
    2011-04-26 23:39:59 -------- d-----w- c:\docume~1\bob\locals~1\applic~1\OEC
    2011-04-26 23:39:45 -------- d-----w- c:\docume~1\bob\locals~1\applic~1\ApexFutures
    2011-04-26 23:39:29 -------- d-----w- c:\program files\OEC
    2011-04-26 23:39:27 -------- d-----w- c:\program files\ApexTrader
    2011-04-26 19:55:00 -------- d-----w- c:\docume~1\alluse~1\applic~1\hssff
    2011-04-26 15:18:17 -------- d-----w- C:\Hotspot Shield
    2011-04-26 15:17:39 506880 ----a-w- c:\program files\mozilla firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor.dll
    2011-04-26 15:17:37 -------- d-----w- c:\program files\Hotspot Shield
    2011-04-26 15:16:05 270800 ----a-w- C:\DM-76.exe
    2011-04-18 12:18:19 -------- d-----w- c:\docume~1\alluse~1\applic~1\aAe06511eMbCp06511
    2011-04-14 14:56:23 -------- d-----w- c:\docume~1\alluse~1\applic~1\jPm06504jIdHj06504
    2011-04-12 17:13:16 -------- d-----w- c:\docume~1\alluse~1\applic~1\gJm06511lGnOa06511
    2011-04-12 16:28:47 -------- d-----w- c:\docume~1\bob\locals~1\applic~1\CRLCommonVdm
    2011-04-12 11:10:36 -------- d-----w- c:\docume~1\bob\applic~1\IObit
    2011-04-11 12:57:38 -------- d-----w- c:\docume~1\bob\applic~1\AVG10
    2011-04-11 12:23:21 -------- d-----w- c:\docume~1\alluse~1\applic~1\MFAData
    2011-04-11 10:40:43 -------- d-----w- c:\program files\ESET
    2011-04-10 21:40:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-04-10 21:40:16 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-04-10 21:40:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-04-10 13:13:23 -------- d-sha-r- C:\cmdcons
    2011-04-10 13:09:33 98816 ----a-w- c:\windows\sed.exe
    2011-04-10 13:09:33 89088 ----a-w- c:\windows\MBR.exe
    2011-04-10 13:09:33 256512 ----a-w- c:\windows\PEV.exe
    2011-04-10 13:09:33 161792 ----a-w- c:\windows\SWREG.exe
    2011-04-09 22:00:34 -------- d-----w- c:\docume~1\bob\applic~1\AVG9
    2011-04-09 15:12:45 -------- d-----w- c:\docume~1\alluse~1\applic~1\bBe14005kFaLe14005
    2011-04-06 19:43:01 -------- d-----w- C:\wkep
    2011-04-06 19:37:26 -------- d-----w- C:\My Lockbox
    2011-04-06 19:37:02 41912 ----a-w- c:\windows\system32\drivers\FSPFltd.sys
    2011-04-06 17:33:43 -------- d-----w- c:\docume~1\bob\applic~1\Qupim
    2011-04-06 17:33:43 -------- d-----w- c:\docume~1\bob\applic~1\Azawoq
    2011-04-06 13:29:32 -------- d-----w- c:\docume~1\bob\applic~1\ynafzasdaxazdvquptrju3hcert2xtb2
    2011-04-04 17:33:25 -------- d-----w- c:\windows\system32\wbem\repository\FS
    2011-04-04 17:33:25 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-03-30 22:17:22 134480 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
    2011-03-30 13:15:38 -------- d-----w- c:\docume~1\alluse~1\applic~1\iMg28604kIaGl28604
    .
    ==================== Find3M ====================
    .
    2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-07 02:08:13 93552 ----a-w- c:\windows\system32\ElbyCDIO.dll
    2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:06:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 11:41:59 385024 ----a-w- c:\windows\system32\html.iec
    2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
    2011-02-11 13:25:52 229888 ----a-w- c:\windows\system32\fxscover.exe
    2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
    2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
    2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2009-10-03 16:43:23 8410624 ----a-w- c:\program files\HTML Guardian 7.msi
    .
    ============= FINISH: 8:12:01.37 ===============

  9. #9
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi again,

    Probably better to uninstall AVG and leave it uninstalled for now. Otherwise you need to uninstall it each time we run ComboFix. I'll tell you when it's ok to reinstall.

    Are you familiar with C:\DM-76.exe file?

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    Folder::
    c:\documents and settings\All Users\Application Data\aAe06511eMbCp06511
    c:\documents and settings\All Users\Application Data\jPm06504jIdHj06504
    c:\documents and settings\All Users\Application Data\gJm06511lGnOa06511
    c:\documents and settings\zxcasdqwe
    c:\documents and settings\All Users\Application Data\bBe14005kFaLe14005
    c:\documents and settings\Bob\Application Data\Azawoq
    c:\documents and settings\Bob\Application Data\Qupim
    c:\documents and settings\Bob\Application Data\ynafzasdaxazdvquptrju3hcert2xtb2
    c:\documents and settings\All Users\Application Data\iMg28604kIaGl28604

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.


    Adobe Acrobat 6.0.1 Professional is not supported anymore and should be uninstalled.

    Uninstall old Adobe Reader versions and get the latest one ((Adobe Reader X + 10.0.1 update for it)) here or get Foxit Reader here. Make sure you don't (unless you want to) install toolbar if choose Foxit Reader! You may also check free readers introduced here.


    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 25.
    • Click the
      Download
      button to the right.
    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u25-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.



    Run ESET Online Scanner. Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  10. #10
    Member
    Join Date
    Apr 2011
    Posts
    78

    Default

    DM-76.exe is some sort of proxy utility that I've never used. It has been removed.

    CFScript.txt has been run. The log is below.

    Adobe Acrobat 6.0.1 has been uninstalled. I have periodic need to create simple PDF documents. Can you recommend a good free PDF creation utility?

    All Adobe Reader versions have been removed.

    All old Java versions have been removed and JRE 6 Update 25 has been installed.

    Eset and DDS has been run. All logs are below.

    Thank you very much for all your help.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    ComboFix 11-04-28.03 - Bob 04/29/2011 6:19.12.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1468 [GMT -5:00]
    Running from: c:\documents and settings\Bob\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Bob\Desktop\CFScript.txt
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\All Users\Application Data\aAe06511eMbCp06511
    c:\documents and settings\All Users\Application Data\aAe06511eMbCp06511\aAe06511eMbCp06511
    c:\documents and settings\All Users\Application Data\bBe14005kFaLe14005
    c:\documents and settings\All Users\Application Data\bBe14005kFaLe14005\bBe14005kFaLe14005
    c:\documents and settings\All Users\Application Data\gJm06511lGnOa06511
    c:\documents and settings\All Users\Application Data\gJm06511lGnOa06511\gJm06511lGnOa06511
    c:\documents and settings\All Users\Application Data\iMg28604kIaGl28604
    c:\documents and settings\All Users\Application Data\iMg28604kIaGl28604\iMg28604kIaGl28604
    c:\documents and settings\All Users\Application Data\jPm06504jIdHj06504
    c:\documents and settings\All Users\Application Data\jPm06504jIdHj06504\jPm06504jIdHj06504
    c:\documents and settings\Bob\Application Data\Azawoq
    c:\documents and settings\Bob\Application Data\Qupim
    c:\documents and settings\Bob\Application Data\Qupim\buki.cao
    c:\documents and settings\Bob\Application Data\Qupim\buki.cao.0
    c:\documents and settings\Bob\Application Data\ynafzasdaxazdvquptrju3hcert2xtb2
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-03-28 to 2011-04-29 )))))))))))))))))))))))))))))))
    .
    .
    2011-04-26 23:40 . 2011-04-26 23:40 -------- d-----w- c:\documents and settings\Bob\Application Data\ApexFutures
    2011-04-26 23:39 . 2011-04-26 23:39 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\OEC
    2011-04-26 23:39 . 2011-04-26 23:39 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\ApexFutures
    2011-04-26 23:39 . 2011-04-26 23:39 -------- d-----w- c:\program files\OEC
    2011-04-26 23:39 . 2011-04-26 23:39 -------- d-----w- c:\program files\ApexTrader
    2011-04-26 19:55 . 2011-04-26 19:55 -------- d-----w- c:\documents and settings\All Users\Application Data\hssff
    2011-04-26 15:18 . 2011-04-26 15:18 -------- d-----w- C:\Hotspot Shield
    2011-04-26 15:17 . 2010-11-04 18:43 506880 ----a-w- c:\program files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor.dll
    2011-04-26 15:17 . 2011-04-26 15:17 -------- d-----w- c:\program files\Hotspot Shield
    2011-04-12 16:28 . 2011-04-12 23:44 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\CRLCommonVdm
    2011-04-12 11:10 . 2011-04-12 11:10 -------- d-----w- c:\documents and settings\Bob\Application Data\IObit
    2011-04-11 21:02 . 2011-04-11 21:02 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Application Updater
    2011-04-11 12:57 . 2011-04-11 12:57 -------- d-----w- c:\documents and settings\Bob\Application Data\AVG10
    2011-04-11 12:23 . 2011-04-28 11:22 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
    2011-04-11 12:05 . 2011-04-11 12:06 -------- d-----w- c:\documents and settings\zxcasdqwe
    2011-04-11 10:40 . 2011-04-11 10:40 -------- d-----w- c:\program files\ESET
    2011-04-10 21:40 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-04-10 21:40 . 2011-04-10 21:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-04-10 21:40 . 2010-12-20 23:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-04-09 22:00 . 2011-04-09 22:00 -------- d-----w- c:\documents and settings\Bob\Application Data\AVG9
    2011-04-06 19:43 . 2011-04-27 11:09 -------- d-----w- C:\wkep
    2011-04-06 19:37 . 2011-04-06 19:37 -------- d-----w- C:\My Lockbox
    2011-04-06 19:37 . 2010-07-22 21:13 41912 ----a-w- c:\windows\system32\drivers\FSPFltd.sys
    2011-04-04 17:33 . 2011-04-04 17:33 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-03-30 13:30 . 2011-03-30 13:33 -------- d-----w- c:\documents and settings\Administrator.INSPIRON\Application Data\vlc
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-07 05:33 . 2008-01-13 03:20 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-07 02:08 . 2011-03-07 02:08 93552 ----a-w- c:\windows\system32\ElbyCDIO.dll
    2011-03-04 06:37 . 2004-08-04 10:00 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:21 . 2004-08-04 10:00 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:06 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:06 . 2004-08-04 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:06 . 2004-08-04 10:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 11:41 . 2004-08-04 10:00 385024 ----a-w- c:\windows\system32\html.iec
    2011-02-17 13:18 . 2004-08-04 10:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-02-17 13:18 . 2004-08-04 10:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys
    2011-02-17 12:32 . 2009-04-16 16:36 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2011-02-15 12:56 . 2004-08-04 10:00 290432 ----a-w- c:\windows\system32\atmfd.dll
    2011-02-11 13:25 . 2008-05-15 12:38 229888 ----a-w- c:\windows\system32\fxscover.exe
    2011-02-09 13:53 . 2004-08-04 10:00 270848 ----a-w- c:\windows\system32\sbe.dll
    2011-02-09 13:53 . 2004-08-04 10:00 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-02-08 13:33 . 2004-08-04 10:00 978944 ----a-w- c:\windows\system32\mfc42.dll
    2011-02-08 13:33 . 2004-08-04 10:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2011-02-02 07:58 . 2008-01-13 03:19 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2009-10-03 16:43 . 2009-10-03 16:43 8410624 ----a-w- c:\program files\HTML Guardian 7.msi
    2009-08-20 23:58 . 2009-08-20 23:58 27976 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
    2009-08-20 23:58 . 2009-08-20 23:58 126360 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
    2009-08-20 23:58 . 2009-08-20 23:58 98712 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
    .
    .
    ((((((((((((((((((((((((((((( SnapShot_2011-04-28_11.16.20 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2011-04-29 11:12 . 2011-04-29 11:12 16384 c:\windows\temp\Perflib_Perfdata_ddc.dat
    + 2011-04-29 11:11 . 2011-04-29 11:11 16384 c:\windows\temp\Perflib_Perfdata_7dc.dat
    + 2011-04-29 11:12 . 2011-04-29 11:12 16384 c:\windows\temp\Perflib_Perfdata_744.dat
    + 2011-04-29 10:55 . 2011-04-29 10:55 348160 c:\windows\ERDNT\AutoBackup\4-29-2011\Users\00000002\UsrClass.dat
    + 2011-04-29 10:55 . 2005-10-20 17:02 163328 c:\windows\ERDNT\AutoBackup\4-29-2011\ERDNT.EXE
    + 2011-04-29 10:55 . 2011-04-29 10:55 11808768 c:\windows\ERDNT\AutoBackup\4-29-2011\Users\00000001\ntuser.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2011-03-07 4886136]
    "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-03-09 26103592]
    "OpenDNS Updater"="c:\program files\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
    "EPSON Stylus CX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE" [2005-02-07 98304]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
    "AdobeVersionCue"="c:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe" [2003-10-13 1732608]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
    "RTHDCPL"="RTHDCPL.EXE" [2008-02-05 16859648]
    "Norton Ghost 14.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2008-01-20 2245984]
    "ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2005-02-16 221184]
    "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-01-27 63048]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "mylbx"="c:\program files\My Lockbox\mylbx.exe" [2011-03-27 1900864]
    .
    c:\documents and settings\Bob\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
    Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1996-11-17 111376]
    Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1996-11-17 51984]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Acrobat Assistant.lnk - c:\program files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 217194]
    Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-1-24 110592]
    Omega Research Task Scheduler.lnk - c:\program files\Omega Research\Program\orschd.exe [2008-3-19 148480]
    PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [N/A]
    Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
    2010-12-08 19:11 87424 ----a-w- c:\windows\system32\LMIinit.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "mixer"=DrvTrNTm.dll
    "wave"=DrvTrNTm.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
    "c:\\WINDOWS\\system32\\dpvsetup.exe"=
    "c:\\Program Files\\1stWORKS\\hotCommCL\\BIN\\HotComm.exe"=
    "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\WINDOWS\\system32\\hkcmd.exe"=
    "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
    "c:\\Program Files\\NinjaTrader 7\\bin\\NinjaTrader.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
    "2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)
    .
    R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [4/6/2011 2:37 PM 41912]
    R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
    R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [10/5/2010 7:39 PM 374152]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/27/2010 12:22 PM 12856]
    R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/4/2004 5:00 AM 5120]
    R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [12/20/2007 5:13 PM 1553896]
    R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [5/10/2009 4:26 PM 127496]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS --> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
    S3 NLNdisMP;NLNdisMP;c:\windows\system32\DRIVERS\nlndis.sys --> c:\windows\system32\DRIVERS\nlndis.sys [?]
    S3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\DRIVERS\nlndis.sys --> c:\windows\system32\DRIVERS\nlndis.sys [?]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-04-28 c:\windows\Tasks\User_Feed_Synchronization-{1FF685FF-AF79-4E0B-A492-555956BF9C7C}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\program files\Common Files\Microsoft Shared\Stationery\Blank.htm
    uStart Page = hxxp://twitter.com/
    uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=%s
    FF - ProfilePath - c:\documents and settings\Bob\Application Data\Mozilla\Firefox\Profiles\vw9a9lod.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=685749&p=
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - Ext: afurladvisor: afurladvisor@anchorfree.com - c:\program files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com
    FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
    FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
    FF - Ext: Echofon: twitternotifier@naan.net - %profile%\extensions\twitternotifier@naan.net
    FF - Ext: PDF Download: {37E4D8EA-8BDA-4831-8EA1-89053939A250} - %profile%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
    FF - Ext: Ant Video Downloader: anttoolbar@ant.com - %profile%\extensions\anttoolbar@ant.com
    FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
    FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG10\Firefox4
    FF - user.js: capability.policy.policynames - allowclipboard
    FF - user.js: capability.policy.allowclipboard.sites - hxxp://www.insidefutures.com http://www.futuresknowledge.com
    FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
    FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-04-29 06:26
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'winlogon.exe'(832)
    c:\windows\system32\LMIinit.dll
    c:\windows\system32\LMIRfsClientNP.dll
    .
    Completion time: 2011-04-29 06:28:47
    ComboFix-quarantined-files.txt 2011-04-29 11:28
    ComboFix2.txt 2011-04-28 11:18
    ComboFix3.txt 2011-04-10 20:02
    ComboFix4.txt 2011-04-10 15:37
    .
    Pre-Run: 84,648,558,592 bytes free
    Post-Run: 84,630,118,400 bytes free
    .
    - - End Of File - - AC971CB91C989C15AC9D2BD0F88DB1C1



    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



    Eset Log

    C:\Program Files\Hotspot Shield\bin\openvpnas.exe a variant of Win32/HotSpotShield application cleaned by deleting - quarantined
    C:\System Volume Information\_restore{6068B9D1-1234-4DDA-9F1C-9B42EECF3E57}\RP407\A0078033.exe a variant of Win32/HotSpotShield application deleted - quarantined
    C:\System Volume Information\_restore{6068B9D1-1234-4DDA-9F1C-9B42EECF3E57}\RP419\A0081969.exe a variant of Win32/HotSpotShield application cleaned by deleting - quarantined



    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


    .
    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Bob at 8:30:49.06 on Fri 04/29/2011
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_25
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1238 [GMT -5:00]
    .
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost.exe -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Hotspot Shield\bin\hsswd.exe
    C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Norton Ghost\Agent\VProTray.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\Program Files\My Lockbox\mylbx.exe
    C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
    C:\Program Files\DAEMON Tools Lite\DTLite.exe
    C:\Program Files\Omega Research\Program\orschd.exe
    C:\Program Files\Norton Ghost\Agent\VProSvc.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\Bob\Desktop\dds.scr
    .
    ============== Pseudo HJT Report ===============
    .
    uLocal Page = c:\program files\common files\microsoft shared\stationery\Blank.htm
    uStart Page = hxxp://twitter.com/
    uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=%s
    mURLSearchHooks: H - No File
    BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 7\SnagItBHO.dll
    BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
    TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 7\SnagItIEAddin.dll
    TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
    TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
    TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
    uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe
    uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized
    uRun: [OpenDNS Updater] "c:\program files\opendns updater\OpenDNSUpdater.exe" /autostart
    uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    mRun: [CloneCDTray] "c:\program files\slysoft\clonecd\CloneCDTray.exe" /s
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [Norton Ghost 14.0] "c:\program files\norton ghost\agent\VProTray.exe"
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
    mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
    mRun: [mylbx] c:\program files\my lockbox\mylbx.exe /a
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    StartupFolder: c:\docume~1\bob\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\bob\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\FINDFAST.EXE
    StartupFolder: c:\docume~1\bob\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\omegar~1.lnk - c:\program files\omega research\program\orschd.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\paltalk.lnk - c:\program files\paltalk messenger\paltalk.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - c:\program files\plotsoft\pdfill\DownloadPDF.exe
    IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {254AA86E-5655-4518-AA87-185D7CC41801} - hxxps://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
    Notify: igfxcui - igfxdev.dll
    Notify: LMIinit - LMIinit.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\docume~1\bob\applic~1\mozilla\firefox\profiles\vw9a9lod.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=685749&p=
    FF - component: c:\documents and settings\bob\application data\mozilla\firefox\profiles\vw9a9lod.default\extensions\dttoolbar@toolbarnet.com\components\DTToolbarFF.dll
    FF - component: c:\documents and settings\bob\application data\mozilla\firefox\profiles\vw9a9lod.default\extensions\twitternotifier@naan.net\platform\winnt\components\nsTwitterFoxSign.dll
    FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
    FF - component: c:\program files\mozilla firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor.dll
    FF - plugin: c:\documents and settings\bob\application data\mozilla\firefox\profiles\vw9a9lod.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\np32dsw.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\NPDOC.DLL
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npdrmv2.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npdsplay.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\NPJPI142_06.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nppdf32.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nppl3260.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nprfxins.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nprjplug.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\nprpjplug.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\NPSVG3.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npwmsdrm.dll
    FF - plugin: c:\program files\netscape\navigator\program\plugins\npyacs.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: afurladvisor: afurladvisor@anchorfree.com - c:\program files\mozilla firefox\extensions\afurladvisor@anchorfree.com
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
    FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
    FF - Ext: LogMeIn, Inc. Remote Access Plugin: LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
    FF - Ext: Echofon: twitternotifier@naan.net - %profile%\extensions\twitternotifier@naan.net
    FF - Ext: PDF Download: {37E4D8EA-8BDA-4831-8EA1-89053939A250} - %profile%\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
    FF - Ext: Ant Video Downloader: anttoolbar@ant.com - %profile%\extensions\anttoolbar@ant.com
    FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
    FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg10\Firefox4
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: capability.policy.policynames - allowclipboard
    FF - user.js: capability.policy.allowclipboard.sites - hxxp://www.insidefutures.com http://www.futuresknowledge.com
    FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
    FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [2011-4-6 41912]
    R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
    R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2010-10-5 374152]
    R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-1-27 12856]
    R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-7-13 47640]
    R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2004-8-4 5120]
    R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2007-12-20 1553896]
    R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [2009-5-10 127496]
    S0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys --> c:\windows\system32\drivers\avgarkt.sys [?]
    S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
    S1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\avgarcln.sys --> c:\windows\system32\drivers\AvgArCln.sys [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" --> c:\program files\lavasoft\ad-aware\AAWService.exe [?]
    S3 NLNdisMP;NLNdisMP;c:\windows\system32\drivers\nlndis.sys --> c:\windows\system32\drivers\nlndis.sys [?]
    S3 NLNdisPT;NetLimiter Ndis Protocol Service;c:\windows\system32\drivers\nlndis.sys --> c:\windows\system32\drivers\nlndis.sys [?]
    S4 LMIRfsClientNP;LMIRfsClientNP; [x]
    .
    =============== Created Last 30 ================
    .
    2011-04-29 12:01:58 73728 ----a-w- c:\windows\system32\javacpl.cpl
    2011-04-29 12:01:58 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-04-29 12:01:58 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    2011-04-26 23:40:11 -------- d-----w- c:\docume~1\bob\applic~1\ApexFutures
    2011-04-26 23:39:59 -------- d-----w- c:\docume~1\bob\locals~1\applic~1\OEC
    2011-04-26 23:39:45 -------- d-----w- c:\docume~1\bob\locals~1\applic~1\ApexFutures
    2011-04-26 23:39:29 -------- d-----w- c:\program files\OEC
    2011-04-26 23:39:27 -------- d-----w- c:\program files\ApexTrader
    2011-04-26 19:55:00 -------- d-----w- c:\docume~1\alluse~1\applic~1\hssff
    2011-04-26 15:18:17 -------- d-----w- C:\Hotspot Shield
    2011-04-26 15:17:39 506880 ----a-w- c:\program files\mozilla firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor.dll
    2011-04-26 15:17:37 -------- d-----w- c:\program files\Hotspot Shield
    2011-04-12 16:28:47 -------- d-----w- c:\docume~1\bob\locals~1\applic~1\CRLCommonVdm
    2011-04-12 11:10:36 -------- d-----w- c:\docume~1\bob\applic~1\IObit
    2011-04-11 12:57:38 -------- d-----w- c:\docume~1\bob\applic~1\AVG10
    2011-04-11 12:23:21 -------- d-----w- c:\docume~1\alluse~1\applic~1\MFAData
    2011-04-11 10:40:43 -------- d-----w- c:\program files\ESET
    2011-04-10 21:40:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-04-10 21:40:16 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-04-10 21:40:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-04-10 13:13:23 -------- d-sha-r- C:\cmdcons
    2011-04-10 13:09:33 98816 ----a-w- c:\windows\sed.exe
    2011-04-10 13:09:33 89088 ----a-w- c:\windows\MBR.exe
    2011-04-10 13:09:33 256512 ----a-w- c:\windows\PEV.exe
    2011-04-10 13:09:33 161792 ----a-w- c:\windows\SWREG.exe
    2011-04-09 22:00:34 -------- d-----w- c:\docume~1\bob\applic~1\AVG9
    2011-04-06 19:43:01 -------- d-----w- C:\wkep
    2011-04-06 19:37:26 -------- d-----w- C:\My Lockbox
    2011-04-06 19:37:02 41912 ----a-w- c:\windows\system32\drivers\FSPFltd.sys
    2011-04-04 17:33:25 -------- d-----w- c:\windows\system32\wbem\repository\FS
    2011-04-04 17:33:25 -------- d-----w- c:\windows\system32\wbem\Repository
    .
    ==================== Find3M ====================
    .
    2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-07 02:08:13 93552 ----a-w- c:\windows\system32\ElbyCDIO.dll
    2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
    2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-02-22 23:06:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-02-22 11:41:59 385024 ----a-w- c:\windows\system32\html.iec
    2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
    2011-02-11 13:25:52 229888 ----a-w- c:\windows\system32\fxscover.exe
    2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
    2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
    2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
    2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2009-10-03 16:43:23 8410624 ----a-w- c:\program files\HTML Guardian 7.msi
    .
    ============= FINISH: 8:31:28.39 ===============

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •