RogueKiller.exe then HijackThis.exe then Malwarebytes
The virus popups disappeared but Malwarebytes issued warnings (approx. every 6 seconds) that it was blocking outbound traffic to malicious websites.
Also noticed in Task Manager processes that PING.EXE was running. Stopped the process but it starts back up within a few minutes.
Found Apple Itune software on the computer, which I had not knowingly loaded. Therefore I deleted all Apple software including QuickTime.
Installed and ran RegServe which found and fixed about 1500 registry entries.
Ran a couple of McAfee and Malwarebytes scans that find no infections. However the blocked outbound traffic to malicious websites and the PING.EXE process still persist.
First attempt to run a GMER scan locked the computer. I had to cold reboot. Second attempt completed but displayed this warning: “GMER has found system modification caused by ROOTKIT Activity”
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Run by Owner at 16:57:55 on 2011-12-14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1471.828 [GMT -5:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Cobian Backup 10\cbVSCService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\RegServe\RSListener.exe
C:\Program Files\Cobian Backup 10\cbInterface.exe
C:\Program Files\Cobian Backup 10\cbService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\dllhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://my.att.net/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://us10.hpwis.com/
uDefault_Search_URL = hxxp://srch-us10.hpwis.com/
uSearch Bar = hxxp://www.google.com/ie
uWindow Title = Microsoft Internet Explorer provided by EarthLink
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://srch-us10.hpwis.com/
mWindow Title = Microsoft Internet Explorer provided by EarthLink
uInternet Settings,ProxyOverride = localhost
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110514185545.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: {BDF3E430-B101-42AD-A544-FADC6B084872} - No File
BHO: ZeonIEEventHelper Class: {da986d7d-ccaf-47b2-84fe-bfa1549bebf9} - c:\program files\nuance\pdf professional 5\bin\ZeonIEFavClient.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: HP View: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No File
TB: Nuance PDF: {e3286bf1-e654-42ff-b4a6-5e111731df6b} - c:\program files\nuance\pdf professional 5\bin\ZeonIEFavClient.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
EB: hp view: {8f4902b6-6c04-4ade-8052-aa58578a21bd} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {AAE89D95-75CC-4708-87E5-60CF917B7B5B} - No File
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [RSListener] c:\program files\regserve\RSListener.exe
mRun: [Cobian Backup 10 Interface] "c:\program files\cobian backup 10\cbInterface.exe" -service
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
IE: Append the content of the link to existing PDF file - c:\program files\nuance\pdf professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Append the content of the selected links to existing PDF file - c:\program files\nuance\pdf professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
IE: Append to existing PDF file - c:\program files\nuance\pdf professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Create PDF file - c:\program files\nuance\pdf professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF file from the content of the link - c:\program files\nuance\pdf professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF files from the selected links - c:\program files\nuance\pdf professional 5\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Open with Nuance PDF Converter 5.0 - c:\program files\nuance\pdf professional 5\cnvres_eng.dll /100
IE: {4CA62B22-C2CB-459d-A8F6-5FE5B1053C80} - c:\program files\thesearchaccelerator\ucmorehelp.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {33740AEB-2856-4004-B84B-37E2C0D4F13D} - {AAE89D95-75CC-4708-87E5-60CF917B7B5B}
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
LSP: mswsock.dll
Trusted Zone: chase.com\chaseonline
Trusted Zone: motive.com\pattta.att
Trusted Zone: motive.com\patttbc.att
Trusted Zone: schwab.com\investing
DPF: DirectAnimation Java Classes - file://c:\windows\system32\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\system32\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: symsupportutil - hxxps://www-secure.symantec.com/techsupp/activedata/symsupportutil.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} - hxxp://office.microsoft.com/productupdates/content/opuc.cab
DPF: {607DF741-7D0A-11D4-9EDC-005004189684} - hxxp://www.ucmore.com/download/UCmoreIEx.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - hxxp://www.installengine.com/engine/isetup.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38117.7716550926
DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_0_03-win.cab
DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} - hxxp://windowsupdate.microsoft.com/R1062/V31Controls/x86/w98/en/actsetup.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} - hxxp://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - hxxps://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
TCP: Interfaces\{4CCAEDC7-BE76-4CC8-AE30-6D27A2146F23} : NameServer = 4.2.2.1,4.2.2.2
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxsrvc.dll
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "c:\progra~1\outloo~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "c:\progra~1\outloo~1\setup50.exe" /app:oe /caller:ie50 /user /install - "c:\progra~1\outloo~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "c:\progra~1\outloo~1\setup50.exe" /app:oe /caller:ie50 /user /install - "c:\progra~1\outloo~1\setup50.exe" /app:oe /caller:win9x /user /install - "c:\progra~1\outloo~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install
mASetup: {44BBA851-CC51-11CF-AAFA-00AA00B6015C} - rundll32.exeadvpack.dll
mASetup: {5A8D6EE0-3E18-11D0-821E-444553540000} - rundll32.exe advpack.dll,LaunchINFSectionEx c:\windows\inf\icw.inf,PerUserStub,,36
mASetup: {7790769C-0471-11d2-AF11-00C04FA35D02} - "c:\progra~1\outloo~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
mASetup: {7790769C-0471-11d2-AF11-00C04FA35D02} - "c:\progra~1\outloo~1\setup50.exe" /app:wab /caller:ie50 /user /install - "c:\progra~1\outloo~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
mASetup: {7790769C-0471-11d2-AF11-00C04FA35D02} - "c:\progra~1\outloo~1\setup50.exe" /app:wab /caller:ie50 /user /install - "c:\progra~1\outloo~1\setup50.exe" /app:wab /caller:win9x /user /install - "c:\progra~1\outloo~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
mASetup: {89820200-ECBD-11cf-8B85-00AA005B4395} - rundll32.exe advpack.dll,LaunchINFSectionEx c:\windows\system32\ie4uinit.inf,Shell.UserStub,,36
mASetup: {9EF0045A-CDD9-438e-95E6-02B9AFEC8E11} - c:\windows\system32\updcrl.exe -e -u c:\windows\system32\verisignpub1.crl
mASetup: >IEPerUser - RUNDLL32.EXE IEDKCS32.DLL,BrandIE4 SIGNUP
mASetup: >PerUser_MSN_Clean - c:\windows\msnmgsr1.exe
mASetup: AppletsPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection appletsperuser 64 c:\windows\inf\applets.inf
mASetup: Chl99 - rundll32.exe advpack.dll,LaunchINFSection c:\windows\inf\chl99.inf,InstallUser
mASetup: FontsPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection fontsperuser 64 c:\windows\inf\fonts.inf
mASetup: MmoptJunglePerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection mmoptjungleperuser 64 c:\windows\inf\mmopt.inf
mASetup: MmoptMusicaPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection mmoptmusicaperuser 64 c:\windows\inf\mmopt.inf
mASetup: MmoptRegisterPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection mmoptregisterperuser 64 c:\windows\inf\mmopt.inf
mASetup: MmoptRobotzPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection mmoptrobotzperuser 64 c:\windows\inf\mmopt.inf
mASetup: MmoptUtopiaPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection mmoptutopiaperuser 64 c:\windows\inf\mmopt.inf
mASetup: MotownAvivideoPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection motownavivideoperuser 64 c:\windows\inf\motown.inf
mASetup: MotownMmsysPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection motownmmsysperuser 64 c:\windows\inf\motown.inf
mASetup: MotownMPlayPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection motownmplayperuser 64 c:\windows\inf\mplay98.inf
mASetup: MotownRecPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection motownrecperuser 64 c:\windows\inf\motown.inf
mASetup: NetservrPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection netservrperuser 64 c:\windows\inf\netservr.inf
mASetup: OlsAolPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection olsaolperuser 64 c:\windows\inf\ols.inf
mASetup: OlsAttPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection olsattperuser 64 c:\windows\inf\ols.inf
mASetup: OlsCompuservePerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection olscompuserveperuser 64 c:\windows\inf\ols.inf
mASetup: OlsMsnPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection olsmsnperuser 64 c:\windows\inf\ols.inf
mASetup: OlsPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection olsperuser 64 c:\windows\inf\ols.inf
mASetup: OlsProdigyPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection olsprodigyperuser 64 c:\windows\inf\ols.inf
mASetup: PerUser_Base - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_base 64 c:\windows\inf\msmail.inf
mASetup: PerUser_Calc_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_calc_inis 64 c:\windows\inf\applets.inf
mASetup: PerUser_CDPlayer_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_cdplayer_inis 64 c:\windows\inf\mmopt.inf
mASetup: PerUser_CharMap_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_charmap_inis 64 c:\windows\inf\appletpp.inf
mASetup: PerUser_ClipBrd_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_clipbrd_inis 64 c:\windows\inf\clip.inf
mASetup: PerUser_CVT_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_cvt_inis 64 c:\windows\inf\applets1.inf
mASetup: PerUser_DCC_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_dcc_inis 64 c:\windows\inf\rna.inf
mASetup: PerUser_Dialer_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_dialer_inis 64 c:\windows\inf\appletpp.inf
mASetup: PerUser_dxxspace_Links - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_dxxspace_links 64 c:\windows\inf\applets1.inf
mASetup: PerUser_Enable_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_enable_inis 64 c:\windows\inf\enable.inf
mASetup: PerUser_ICW_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_icw_inis 0 c:\windows\inf\icw97.inf
mASetup: PerUser_LinkBar_URLs - c:\windows\command\sulfnbk.exe /L
mASetup: PerUser_MSBackup_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_msbackup_inis 64 c:\windows\inf\applets1.inf
mASetup: PerUser_Msinfo - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_msinfo 64 c:\windows\inf\msinfo.inf
mASetup: PerUser_Msinfo2 - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_msinfo2 64 c:\windows\inf\msinfo.inf
mASetup: PerUser_MSWordPad_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_mswordpad_inis 64 c:\windows\inf\wordpad.inf
mASetup: PerUser_netwatch_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_netwatch_inis 64 c:\windows\inf\appletpp.inf
mASetup: PerUser_Onlinelnks_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_onlinelnks_inis 64 c:\windows\inf\appletpp.inf
mASetup: PerUser_Paint_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_paint_inis 64 c:\windows\inf\applets.inf
mASetup: PerUser_Preptool - rundll.exe Setupx.dll,InstallHinfSection Install 64 c:\windows\inf\RUNLAST.INF
mASetup: PerUser_RNA_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_rna_inis 64 c:\windows\inf\rna.inf
mASetup: PerUser_Sysmeter_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_sysmeter_inis 64 c:\windows\inf\appletpp.inf
mASetup: PerUser_Sysmon_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_sysmon_inis 64 c:\windows\inf\appletpp.inf
mASetup: PerUser_Vol - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_vol 64 c:\windows\inf\motown.inf
mASetup: PerUser_winapps_Links - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_winapps_links 64 c:\windows\inf\subase.inf
mASetup: PerUser_winbase_Links - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_winbase_links 64 c:\windows\inf\subase.inf
mASetup: PerUser_Wingames_Inis - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruser_wingames_inis 64 c:\windows\inf\appletpp.inf
mASetup: PerUserOldLinks - rundll.exe c:\windows\system32\setupx.dll,installhinfsection peruseroldlinks 64 c:\windows\inf\appletpp.inf
mASetup: SetupcPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection setupcperuser 64 c:\windows\inf\setupc.inf
mASetup: Shell2PerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection shell2peruser 64 c:\windows\inf\shell2.inf
mASetup: Shell3PerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection shell3peruser 64 c:\windows\inf\shell3.inf
mASetup: ShellPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection shellperuser 64 c:\windows\inf\shell.inf
mASetup: TapiPerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection tapiperuser 64 c:\windows\inf\tapi.inf
mASetup: Theme_MoreWindows_PerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection themes_morewindows_peruser 0 c:\windows\inf\themes.inf
mASetup: Theme_Windows_PerUser - rundll.exe c:\windows\system32\setupx.dll,installhinfsection themes_windows_peruser 0 c:\windows\inf\themes.inf
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\r83foodp.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\opera7\program\plugins\np32dsw.dll
FF - plugin: c:\program files\opera7\program\plugins\npdrmv2.dll
FF - plugin: c:\program files\opera7\program\plugins\npdsplay.dll
FF - plugin: c:\program files\opera7\program\plugins\NPJava11.dll
FF - plugin: c:\program files\opera7\program\plugins\NPJava12.dll
FF - plugin: c:\program files\opera7\program\plugins\NPJava13.dll
FF - plugin: c:\program files\opera7\program\plugins\NPJava32.dll
FF - plugin: c:\program files\opera7\program\plugins\nppl3260.dll
FF - plugin: c:\program files\opera7\program\plugins\nprjplug.dll
FF - plugin: c:\program files\opera7\program\plugins\nprpjplug.dll
FF - plugin: c:\program files\opera7\program\plugins\npwmsdrm.dll
FF - plugin: c:\program files\real\realone player\netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realone player\netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realone player\netscape6\nprpjplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-2-9 387480]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2011-2-9 84200]
R2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\cobian backup 10\cbVSCService.exe [2011-12-13 67584]
R2 CobianBackup10;Cobian Backup 10;c:\program files\cobian backup 10\cbService.exe [2011-12-13 1125376]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-12-6 366152]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2010-11-7 203280]
R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-2-9 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-2-9 271480]
R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-2-9 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-2-9 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-2-9 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-2-9 141792]
R2 PDFProFiltSrv;PDFProFiltSrv;c:\program files\nuance\pdf professional 5\PDFProFiltSrv.exe [2008-2-2 144672]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2011-3-9 92592]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-2-9 56064]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-6 22216]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-2-9 153280]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-2-9 52320]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-2-9 314088]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2011-2-9 88736]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-10 135664]
S2 mrtRate;mrtRate; [x]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-11-10 135664]
S3 itexadsla2;ITeX ADSL PCI NIC Service;c:\windows\system32\drivers\itex95a2.sys [2001-9-11 423552]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2011-2-9 88736]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-2-9 84488]
S3 Usblink;Usblink Driver;c:\windows\system32\drivers\ulink.sys [2004-6-25 37772]
S3 VNic;ULan Network Driver Module;c:\windows\system32\drivers\VNic.sys [2004-6-25 40024]
.
=============== Created Last 30 ================
.
2011-12-13 20:50:09 -------- d-----w- c:\program files\Cobian Backup 10
2011-12-11 22:08:58 11776 ----a-w- c:\windows\system32\RSDefrag.exe
2011-12-11 21:42:54 -------- d-----w- c:\program files\RegServe
2011-12-09 03:23:15 -------- d-----w- c:\windows\SxsCaPendDel
2011-12-08 02:16:20 -------- d-----w- c:\program files\iPod
2011-12-08 02:16:12 -------- d-----w- c:\program files\iTunes
2011-12-08 02:16:12 -------- d-----w- c:\documents and settings\all users\application data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-12-07 04:12:48 -------- d-----w- c:\documents and settings\owner\application data\Malwarebytes
2011-12-07 04:12:29 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-07 04:12:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-05 01:02:23 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
.
==================== Find3M ====================
.
2011-11-13 18:30:10 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 17:00:24.79 ===============
Attached File(s)
-
attach.txt (19.58K)
Number of downloads: 1 -
ark.txt (62.26K)
Number of downloads: 0

Help
This topic is locked

Back to top











