Panda,
Firstly, Thanks for taking the time to help me!
Since originally running the combofix and several other apps, the "Folder Options" option on the windows explorer tools menu and in the control panel has been restored and also I am no longer locked out of the "regedit" app. As far as I know, my problem was repaired. However, I am still worried that the virus is still lurking on my system waiting for the right opportunity to turn back on. That is why I posted to this forum. I wanted to be sure it was removed completely.
Below are the 2 reports you asked to be posted here. Also attached is the "Attach.txt" report generated by the DDS app.
ComboFix 09-06-29.04 - smay 06/30/2009 11:36.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.479.185 [GMT -4:00]
Running from: c:\documents and settings\smay\Desktop\ComboFix.exe
AV: Trend Micro OfficeScan Antivirus *On-access scanning enabled* (Updated) {C543F6E5-C8DF-4641-8211-E4797B709EF0}
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-30 )))))))))))))))))))))))))))))))
.
2009-06-30 12:28 . 2008-04-14 00:12 39424 ----a-w- c:\windows\system32\grpconv.exe
2009-06-30 12:28 . 2008-04-14 00:12 39424 ----a-w- c:\windows\system32\dllcache\grpconv.exe
2009-06-30 11:22 . 2009-06-30 12:06 -------- d-----w- C:\SDFix
2009-06-30 10:56 . 2009-06-30 10:56 578560 ----a-w- c:\windows\system32\dllcache\user32.dll
2009-06-30 10:53 . 2009-06-30 10:53 -------- d-----w- c:\windows\ERUNT
2009-06-19 17:56 . 2009-06-19 17:56 45056 ----a-w- c:\documents and settings\smay\Application Data\Sun\Java\Deployment\cache\6.0\42\15823c2a-5bf2cad6-n\jniwrap.dll
2009-06-18 12:05 . 2009-06-18 12:05 -------- d-----w- c:\documents and settings\smay\etpro
2009-06-18 12:04 . 2009-06-19 19:06 -------- d-----w- C:\data
2009-06-18 12:04 . 2009-06-18 12:04 45056 ----a-w- c:\documents and settings\smay\Application Data\Sun\Java\Deployment\cache\6.0\42\15823c2a-385eb9cb-n\jniwrap.dll
2009-06-12 15:06 . 2009-06-12 15:06 664 ----a-w- c:\windows\system32\d3d9caps.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 11:31 . 2009-02-16 18:44 -------- d-----w- c:\program files\Lavasoft
2009-06-30 11:12 . 2009-03-11 10:07 4728 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2009-06-29 17:04 . 2005-08-02 14:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-29 16:18 . 2008-09-08 16:21 -------- d-----w- c:\program files\Unlocker
2009-06-19 19:13 . 2006-10-27 12:22 -------- d-----w- c:\documents and settings\smay\Application Data\U3
2009-06-18 12:29 . 2005-01-27 16:35 -------- d-----w- c:\documents and settings\smay\Application Data\ICAClient
2009-06-12 15:19 . 2008-03-10 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-06-12 10:55 . 2009-02-16 18:25 10752 ----a-w- c:\windows\DCEBoot.exe
2009-05-26 12:13 . 2005-01-27 16:19 137264 ----a-w- c:\documents and settings\smay\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-22 16:02 . 2009-05-22 16:02 -------- d-----w- c:\documents and settings\smay\Application Data\IObit
2009-05-22 15:52 . 2009-05-22 15:52 -------- d-----w- c:\program files\CCleaner
2009-05-22 15:50 . 2009-05-22 15:31 -------- d-----w- c:\program files\Free Window Registry Repair
2009-05-22 11:39 . 2009-05-15 16:08 153104 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-05-20 17:53 . 2005-08-02 14:17 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-20 17:32 . 2007-06-13 16:15 -------- d-----w- c:\program files\Trend Micro
2009-05-18 18:06 . 2009-05-18 18:06 -------- d-----w- c:\program files\MSSOAP
2009-05-18 18:05 . 2009-05-18 18:05 -------- d-----w- c:\program files\Webroot
2009-05-18 18:04 . 2009-05-18 18:04 164 ----a-w- c:\windows\install.dat
2009-05-18 17:29 . 2009-02-16 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-18 17:26 . 2009-02-17 19:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-18 17:16 . 2009-05-18 16:58 -------- d-----w- c:\documents and settings\smay\Application Data\Lavasoft
2009-05-18 13:21 . 2009-05-14 14:22 -------- d-----w- c:\documents and settings\smay\Application Data\Browser
2009-05-15 16:05 . 2009-05-15 16:05 250744 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-15 11:10 . 2009-05-15 11:10 -------- d-----w- c:\documents and settings\smay\Application Data\uniblue
2009-05-15 11:09 . 2009-05-15 11:09 -------- d-----w- c:\program files\Uniblue
2009-05-14 14:30 . 2009-05-14 14:20 -------- d-----w- c:\program files\PackageFactory
2009-05-12 16:48 . 2009-05-12 16:48 -------- d-----w- c:\program files\FLV Player
2009-05-07 15:32 . 1980-01-01 08:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-05 13:01 . 2006-01-05 11:36 -------- d-----w- c:\documents and settings\smay\Application Data\MSNStockQuote
2009-04-29 04:56 . 1980-01-01 08:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-12-22 06:59 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 1980-01-01 08:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 1980-01-01 08:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2006-05-03 09:06 . 2007-08-06 20:01 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2007-08-06 20:01 31232 --sh--r- c:\windows\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2008-10-15 714024]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-05-19 282624]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
c:\documents and settings\smay\Start Menu\Programs\Startup\
Microsoft Office Outlook 2003.lnk - c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe [2008-4-21 794624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-76569932-1102518160-860360866-2507\Scripts\Logon\0\0]
"Script"=\\winston.luwausa.local\NETLOGON\BVAUDIT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-76569932-1102518160-860360866-2574\Scripts\Logon\0\0]
"Script"=\\winston.luwausa.local\NETLOGON\BVAUDIT.EXE
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD LT Startup Accelerator.lnk]
backup=c:\windows\pss\AutoCAD LT Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
backup=c:\windows\pss\Event Reminder.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"stllssvr"=3 (0x3)
"SSI Survey Client"=2 (0x2)
"SSI Client Installer"=3 (0x3)
"RoxLiveShare9"=2 (0x2)
"MDM"=2 (0x2)
"McAfeeFramework"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"iPodService"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"DWMRCS"=2 (0x2)
"Autodesk Licensing Service"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"RoxWatch9"=2 (0x2)
"RoxMediaDB9"=3 (0x3)
"Roxio Upnp Server 9"=2 (0x2)
"Roxio UPnP Renderer 9"=3 (0x3)
"WRConsumerService"=2 (0x2)
"WebrootSpySweeperService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4500:TCP"= 4500:TCP:DA Remote Management
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32\drivers\dwvkbd.sys [2/15/2007 8:00 AM 26624]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [2/9/2007 3:23 PM 14976]
R2 SLClient;ScriptLogic Service;c:\windows\system32\SLClient.exe [6/8/2005 1:24 PM 534528]
R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\TmXPFlt.sys [9/6/2006 9:27 PM 225296]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [9/6/2006 9:27 PM 36368]
R3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2/7/2007 8:00 AM 3712]
S3 DAmirr;DAmirr;c:\windows\system32\DRIVERS\DAmirr.sys --> c:\windows\system32\DRIVERS\DAmirr.sys [?]
S3 pelmouse;Mouse Suite Driver;c:\windows\system32\drivers\PELMOUSE.SYS [12/22/2004 3:22 AM 16384]
S3 pelusblf;USB Mouse Low Filter Driver;c:\windows\system32\drivers\PELUSBLF.SYS [12/22/2004 3:22 AM 9216]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\Trend Micro\OfficeScan Client\TmProxy.exe [9/9/2008 3:22 PM 652552]
S4 SSI Client Installer;SSI Survey Client Installer Service;c:\windows\system32\SCInstallerNT.exe [10/1/2008 1:02 PM 466944]
S4 SSI Survey Client;SSI Survey Client;c:\program files\Scalable Software\Survey\SSI Survey Client\surveyclientnt.exe [10/1/2008 1:04 PM 90112]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-06-29 c:\windows\Tasks\Microsoft Office Outlook 2003.job
- c:\documents and settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2003.lnk [2008-04-21 17:12]
2009-06-29 c:\windows\Tasks\ToolLogs.job
- c:\windows\system32\ntbackup.exe [1980-01-01 00:12]
2009-06-29 c:\windows\Tasks\ToolLogsBU.job
- c:\windows\system32\ntbackup.exe [1980-01-01 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://msnbc.com/
mStart Page = about:blank
DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} - hxxps://trendsvr.winston.luwausa.local:4343/officescan/console/html/AtxEnc.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-30 11:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2376)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-06-30 11:46
ComboFix-quarantined-files.txt 2009-06-30 15:46
Pre-Run: 6,263,156,736 bytes free
Post-Run: 6,230,781,952 bytes free
163 --- E O F --- 2009-06-30 10:03
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
DDS (Ver_09-06-26.01) - NTFSx86 NETWORK
Run by smay at 6:49:21.35 on Mon 07/13/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.479.258 [GMT -4:00]
AV: Trend Micro OfficeScan Antivirus *On-access scanning disabled* (Outdated) {C543F6E5-C8DF-4641-8211-E4797B709EF0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\smay\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://msnbc.com/
mStart Page = about:blank
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: {9516EB1C-AC77-492D-8FD6-A05AFAC9EA6E} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe"
mRun: [OfficeScanNT Monitor] "c:\program files\trend micro\officescan client\pccntmon.exe" -HideWindow
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\smay\startm~1\programs\startup\micros~1.lnk - c:\windows\installer\{90110409-6000-11d3-8cfe-0150048383c9}\outicon.exe
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {00134F72-5284-44F7-95A8-52A619F70751} - hxxps://trendsvr.winston.luwausa.local:4343/officescan/console/ClientInstall/WinNTChk.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=67633
DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} - hxxps://trendsvr.winston.luwausa.local:4343/officescan/console/ClientInstall/setup.cab
DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/0/f/b/0fb0fab9-7f09-4bb6-86d8-8e791ba99ac5/VirtualEarth3D.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} - hxxps://trendsvr.winston.luwausa.local:4343/officescan/console/html/AtxEnc.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_5.cab
DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl.sun.com/webapps/download/AutoDL?BundleId=26688
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} - hxxp://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32\drivers\dwvkbd.sys [2007-2-15 26624]
S2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [2007-2-9 14976]
S2 SLClient;ScriptLogic Service;c:\windows\system32\SLClient.exe [2005-6-8 534528]
S2 TmFilter;Trend Micro Filter;c:\program files\trend micro\officescan client\TmXPFlt.sys [2006-9-6 225296]
S2 TmPreFilter;Trend Micro PreFilter;c:\program files\trend micro\officescan client\tmpreflt.sys [2006-9-6 36368]
S3 DAmirr;DAmirr;c:\windows\system32\drivers\damirr.sys --> c:\windows\system32\drivers\DAmirr.sys [?]
S3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2007-2-7 3712]
S3 pelmouse;Mouse Suite Driver;c:\windows\system32\drivers\PELMOUSE.SYS [2004-12-22 16384]
S3 pelusblf;USB Mouse Low Filter Driver;c:\windows\system32\drivers\PELUSBLF.SYS [2004-12-22 9216]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\trend micro\officescan client\TmProxy.exe [2008-9-9 652552]
S4 McAfeeFramework;McAfee Framework Service;c:\program files\network associates\common framework\FrameworkService.exe [2005-1-17 102463]
S4 SSI Client Installer;SSI Survey Client Installer Service;c:\windows\system32\SCInstallerNT.exe [2008-10-1 466944]
S4 SSI Survey Client;SSI Survey Client;c:\program files\scalable software\survey\ssi survey client\surveyclientnt.exe [2008-10-1 90112]
=============== Created Last 30 ================
2009-07-10 12:03 <DIR> --ds---- C:\ComboFix
2009-07-10 12:03 389,120 a------- c:\windows\system32\CF2942.exe
2009-07-10 12:02 389,120 a------- c:\windows\system32\CF2760.exe
2009-06-30 11:45 <DIR> --d----- c:\windows\system32\dllcache\cache
2009-06-30 08:28 39,424 a------- c:\windows\system32\grpconv.exe
2009-06-30 08:28 39,424 a------- c:\windows\system32\dllcache\grpconv.exe
2009-06-30 08:20 <DIR> a-dshr-- C:\cmdcons
2009-06-30 08:11 161,792 a------- c:\windows\SWREG.exe
2009-06-30 08:11 155,136 a------- c:\windows\PEV.exe
2009-06-30 08:11 98,816 a------- c:\windows\sed.exe
2009-06-30 07:22 <DIR> --d----- C:\SDFix
2009-06-30 06:56 578,560 a------- c:\windows\system32\dllcache\user32.dll
2009-06-30 06:53 <DIR> --d----- c:\windows\ERUNT
2009-06-18 08:05 <DIR> --d----- c:\documents and settings\smay\etpro
2009-06-18 08:04 <DIR> --d----- C:\data
==================== Find3M ====================
2009-06-30 07:12 4,728 a------- c:\windows\system32\PerfStringBackup.TMP
2009-06-12 06:55 10,752 a------- c:\windows\DCEBoot.exe
2009-05-22 07:39 153,104 a------- c:\windows\system32\drivers\tmcomm.sys
2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll
2009-05-07 11:32 345,600 -------- c:\windows\system32\dllcache\localspl.dll
2009-04-29 00:56 827,392 a------- c:\windows\system32\wininet.dll
2009-04-29 00:56 827,392 a------- c:\windows\system32\dllcache\cache\wininet.dll
2009-04-29 00:56 827,392 -------- c:\windows\system32\dllcache\wininet.dll
2009-04-29 00:56 233,472 -------- c:\windows\system32\dllcache\webcheck.dll
2009-04-29 00:56 1,159,680 -------- c:\windows\system32\dllcache\urlmon.dll
2009-04-29 00:56 671,232 -------- c:\windows\system32\dllcache\mstime.dll
2009-04-29 00:56 105,984 -------- c:\windows\system32\dllcache\url.dll
2009-04-29 00:56 102,912 -------- c:\windows\system32\dllcache\occache.dll
2009-04-29 00:56 44,544 -------- c:\windows\system32\dllcache\pngfilt.dll
2009-04-29 00:56 3,596,288 -------- c:\windows\system32\dllcache\mshtml.dll
2009-04-29 00:56 477,696 -------- c:\windows\system32\dllcache\mshtmled.dll
2009-04-29 00:56 193,024 -------- c:\windows\system32\dllcache\msrating.dll
2009-04-28 05:05 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-04-28 05:05 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2009-04-25 01:27 636,088 -------- c:\windows\system32\dllcache\iexplore.exe
2009-04-25 01:26 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-17 08:26 1,847,168 -------- c:\windows\system32\dllcache\win32k.sys
2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-04-15 10:51 585,216 -------- c:\windows\system32\dllcache\rpcrt4.dll
2009-02-17 10:53 1,848 a------- c:\docume~1\alluse~1\applic~1\SSIHistory.dat
2006-05-03 05:06 163,328 ---shr-- c:\windows\system32\flvDX.dll
2007-02-21 06:47 31,232 ---shr-- c:\windows\system32\msfDX.dll
============= FINISH: 6:50:35.56 ===============
Almost forgot.....here's the Kaspersky report:
Monday, July 13, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Friday, July 10, 2009 20:23:19
Records in database: 2457314
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area Critical Areas
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
C:\Documents and Settings\smay\Start Menu\Programs\Startup
C:\Program Files
C:\WINDOWS
Scan statistics
Files scanned 68942
Threat name 2
Infected objects 5
Suspicious objects 0
Duration of the scan 02:12:51
File name Threat name Threats count
C:\Program Files\DesktopAuthority\DesktopAuthority.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a 1
C:\Program Files\DesktopAuthority\ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.b 1
C:\Program Files\DesktopAuthority\ramaint.exe.001.bak Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a 1
C:\Program Files\DesktopAuthority\ramaint.exe.002.bak Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a 1
C:\Program Files\DesktopAuthority\ramaint.exe.003.bak Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.b 1
The selected area was scanned.