Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Multiple Items - Cause Possibly Dopewars?


  • This topic is locked This topic is locked
7 replies to this topic

#1 L. Soule

L. Soule

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Taunton, MA, USA
  • Local time:02:39 PM

Posted 16 April 2008 - 03:56 PM

Hello there,

I'm a great fan of this forum, and have used it often to diagnose and fix my computer. However, this time I'm not able to take care of the problem on my own, thus I've come for assistance.

My brother recently returned home from an extended stay away, and attempted to make up for what downloads he missed. Obviously, this resulted in his laptop becoming considerably infected. Being the most tech savvy in my family, I've been attempting to help him resolve the problem.

His largest problem seems to be with the vast amount of pop-ups surfacing. It gets to the point where there are several iexplore.exe processes going on at once, each straining his cpu heavily. Other than that, both his Firefox and IE homepages were hijacked ( firefox was hijacked to ffsearch.com - he changed the IE homepage before I got ahold of the url ). The browsers also stop working after a bit of time, presumably because of the strain on his cpu.

Before coming here, I attempted to clean up the problem by installing McAfee security center, and then running its virus scan. I also used Spydoctor, from google's pack. They both came up with results, and I deleted everything they picked up. I then ran Kaspersk, and dss.exe.

After discussing the situation with my brother, I've come to the conclusion that his installation of Dopewars is the main culprit. I'm sure it might have been other items, but that is the only program I can really identify as being problematic. He couldn't really remember much else he had downloaded - a lot of music, from various sources - and so I'm a bit in the dark.

I hope this information is helpful. If I can provide anymore, please ask, and I will do my best to add onto it.

Deckard's System Scanner v20071014.68
Run by dayne on 2008-04-16 16:05:04
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- Last 5 Restore Point(s) --
21: 2008-04-15 18:45:14 UTC - RP265 - Spyware Doctor: Cleaning Threats
20: 2008-04-15 08:35:39 UTC - RP263 - Removed Norton Security Scan
19: 2008-04-15 01:13:52 UTC - RP262 - Windows Defender Checkpoint
18: 2008-04-14 23:41:09 UTC - RP260 - Windows Defender Checkpoint
17: 2008-04-14 21:21:56 UTC - RP258 - Windows Defender Checkpoint


-- First Restore Point --
1: 2008-04-05 06:18:57 UTC - RP239 - Removed iTunes


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as dayne.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:08:50 PM, on 4/16/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Toshiba\IVP\ISM\pinger.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Windows\system32\svchost.exe
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\explorer.exe
C:\Windows\System32\Rundll32.exe
C:\Windows\System32\Rundll32.exe
C:\Windows\system32\WUDFHost.exe
C:\Users\dayne\AppData\Roaming\U3\000158708110158C\LaunchPad.exe
C:\Users\dayne\Desktop\dss.exe
C:\Windows\System32\svchost.exe
c:\PROGRA~1\mcafee\mpf\mc\mpfalert.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\dayne\Desktop\dayne.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kaspersky.com/virusscanner
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dcads - {733716E1-76D2-4003-AC39-845281C0EF85} - C:\Windows\system32\nsfB75E.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: nextads browser optimizer - {90ee6848-d086-25fd-4b25-73d4ae6a5c38} - C:\Windows\system32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\vtUmJYss.dll,#1
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll" DllInit
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\dayne\AppData\Local\Temp\xxyawxwV.dll,c
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\dayne\AppData\Local\Temp\fccdATll.dll,#1
O4 - HKCU\..\Run: [Fast mix] "C:\ProgramData\SIXTH TWO TWO.rq6qp"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BM4feffca8] Rundll32.exe "C:\Users\dayne\AppData\Local\Temp\mjwwbfds.dll",s
O4 - HKCU\..\Run: [MS Juan] rundll32 "C:\Users\dayne\AppData\Local\Temp\esaekuiu.dll",run
O4 - HKCU\..\Run: [4cdccf34] rundll32.exe "C:\Users\dayne\AppData\Local\Temp\fpsrlygi.dll",b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P2 /q C:\Users\dayne\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WA8LNGUE\TCODE_~2.SH! (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P2 /q C:\Users\dayne\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WA8LNGUE\TCODE_~2.SH! (User 'Default user')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 13663 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

S4 KR3NPXP - c:\windows\system32\drivers\kr3npxp.sys <Not Verified; TOSHIBA CORPORATION; TOSHIBA RAID>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 CFSvcs (ConfigFree Service) - c:\program files\toshiba\configfree\cfsvcs.exe <Not Verified; TOSHIBA CORPORATION; ConfigFree™>
R2 TNaviSrv (TOSHIBA Navi Support Service) - c:\program files\toshiba\toshiba dvd player\tnavisrv.exe <Not Verified; TOSHIBA Corporation; TOSHIBA DVD Player>
R2 TODDSrv (TOSHIBA Optical Disc Drive Service) - c:\windows\system32\toddsrv.exe <Not Verified; TOSHIBA Corporation; TDCSrv Application>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-04-16 16:02:33 418 --ah----- C:\Windows\Tasks\User_Feed_Synchronization-{66F1B511-026D-4EC3-B6B7-E13E4509186D}.job
2008-04-15 09:22:50 332 --a------ C:\Windows\Tasks\McQcTask.job
2008-04-15 09:22:50 340 --a------ C:\Windows\Tasks\McDefragTask.job


-- Files created between 2008-03-16 and 2008-04-16 -----------------------------

2008-04-16 11:56:28 0 d-------- C:\Users\All Users\Kaspersky Lab
2008-04-16 11:56:25 0 d-------- C:\Windows\system32\Kaspersky Lab
2008-04-15 13:07:12 0 d-------- C:\Program Files\Spyware Doctor
2008-04-15 09:18:23 143360 --a------ C:\Windows\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>
2008-04-15 09:13:15 0 d-------- C:\Program Files\McAfee.com
2008-04-15 09:13:05 0 d-------- C:\Program Files\Common Files\McAfee
2008-04-15 09:13:01 0 d-------- C:\Program Files\McAfee
2008-04-15 03:51:47 0 d-------- C:\Users\All Users\Google Updater
2008-04-14 15:57:43 0 d--hs---- C:\Users\dayne\'
2008-04-14 15:54:03 86144 --a------ C:\Windows\system32\drivers\mrxsmbb.sys
2008-04-14 15:53:50 267 --a------ C:\Windows\system32\6164.bat
2008-04-14 15:53:48 0 d--hs---- C:\Windows\ZGF5bmU
2008-04-14 15:53:46 35840 --a------ C:\Windows\system32\vtUmJYss.dll
2008-04-14 15:53:44 0 d-------- C:\Program Files\Common Files\?icrosoft.NET
2008-04-14 15:53:42 0 d-------- C:\Windows\system32\vFi
2008-04-14 15:53:42 0 d-------- C:\Windows\system32\pinz1
2008-04-14 15:53:42 0 d-------- C:\Windows\system32\IDE2
2008-04-14 15:53:42 0 d-------- C:\Windows\system32\ExTmp
2008-04-14 15:53:39 0 d-------- C:\Windows\system32\bharebio05
2008-04-14 15:53:39 0 d-------- C:\Temp
2008-04-14 15:53:22 62464 --a------ C:\Windows\system32\bszip.dll <Not Verified; BigSpeedSoft; BigSpeed Zip DLL>
2008-04-13 14:54:19 0 d-------- C:\Program Files\Camfrog
2008-04-13 14:38:20 0 d-------- C:\Windows\PaltalkScene
2008-04-13 14:38:20 0 d-------- C:\Program Files\Paltalk Messenger
2008-04-13 00:21:05 0 d-------- C:\Program Files\AvPropPlugin
2008-04-12 23:54:37 0 d-------- C:\Users\All Users\Logishrd
2008-04-12 23:54:27 0 d-------- C:\Users\All Users\Logitech
2008-04-12 23:54:26 0 d-------- C:\Program Files\Logitech
2008-04-12 23:52:40 0 d-------- C:\Program Files\Common Files\logishrd
2008-04-12 21:00:06 0 d-------- C:\Users\All Users\Admin Inter 1 Mags
2008-04-12 20:59:46 0 d-------- C:\Users\All Users\File bold bib
2008-04-12 20:48:03 0 d-------- C:\Windows\system32\Adobe
2008-04-10 11:12:12 329728 --a------ C:\Windows\system32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll
2008-04-08 00:27:36 0 d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-05 02:15:51 0 d-------- C:\Program Files\Yahoo!
2008-04-04 20:09:30 0 d-------- C:\Program Files\QuickTime
2008-04-04 20:09:28 0 d-------- C:\Users\All Users\Apple Computer
2008-04-03 17:35:52 0 d-------- C:\Users\Leon\Shared
2008-04-03 17:35:50 0 d-------- C:\Users\Leon\Incomplete
2008-04-03 13:53:52 0 dr------- C:\Users\Leon\Searches
2008-04-03 13:53:41 0 dr------- C:\Users\Leon\Contacts
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\Templates
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\Start Menu
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\SendTo
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\Recent
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\PrintHood
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\NetHood
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\My Documents
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\Local Settings
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\Cookies
2008-04-03 13:53:36 0 d--hs---- C:\Users\Leon\Application Data
2008-04-03 13:53:35 0 dr------- C:\Users\Leon\Videos
2008-04-03 13:53:35 0 dr------- C:\Users\Leon\Saved Games
2008-04-03 13:53:35 0 dr------- C:\Users\Leon\Pictures
2008-04-03 13:53:35 1048576 --ahs---- C:\Users\Leon\NTUSER.DAT
2008-04-03 13:53:35 0 dr------- C:\Users\Leon\Music
2008-04-03 13:53:35 0 dr------- C:\Users\Leon\Links
2008-04-03 13:53:35 0 dr------- C:\Users\Leon\Favorites
2008-04-03 13:53:35 0 dr------- C:\Users\Leon\Downloads
2008-04-03 13:53:35 0 dr------- C:\Users\Leon\Documents
2008-04-03 13:53:35 0 dr------- C:\Users\Leon\Desktop
2008-04-03 13:53:35 0 d--h----- C:\Users\Leon\AppData
2008-04-02 17:59:20 2560 --a------ C:\Windows\_MSRSTRT.EXE
2008-03-29 12:00:51 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-29 11:59:37 0 d-------- C:\Users\All Users\Symantec
2008-03-29 11:57:53 0 d-a------ C:\Users\All Users\TEMP
2008-03-29 03:17:47 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-29 03:17:42 0 d-------- C:\Program Files\Windows Live
2008-03-29 03:17:07 0 d-------- C:\Users\All Users\WLInstaller
2008-03-28 03:24:45 0 d-------- C:\Users\All Users\Azureus
2008-03-24 23:49:05 0 d-------- C:\Program Files\Bonjour
2008-03-24 23:47:17 0 d-------- C:\Users\All Users\Apple
2008-03-23 21:11:13 724992 --a------ C:\Windows\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2008-03-23 21:11:13 0 d-------- C:\Program Files\EO Video
2008-03-20 20:56:21 0 d-------- C:\Program Files\Common Files\Real


-- Find3M Report ---------------------------------------------------------------

2008-04-16 14:15:20 0 d-------- C:\Users\dayne\AppData\Roaming\U3
2008-04-15 14:46:07 0 d-------- C:\Program Files\Common Files
2008-04-15 13:07:12 0 d-------- C:\Users\dayne\AppData\Roaming\PC Tools
2008-04-15 03:51:58 0 d-------- C:\Program Files\Google
2008-04-14 16:06:31 0 d-------- C:\Users\dayne\AppData\Roaming\LimeWire
2008-04-14 16:05:43 0 d-------- C:\Program Files\LimeWire
2008-04-14 15:53:44 0 d-------- C:\Program Files\Common Files\?icrosoft.NET
2008-04-14 15:38:30 0 d-------- C:\Users\dayne\AppData\Roaming\Yahoo!
2008-04-14 15:37:05 0 d-------- C:\Users\dayne\AppData\Roaming\MP3Rocket
2008-04-13 14:54:51 0 d-------- C:\Users\dayne\AppData\Roaming\Camfrog
2008-04-13 14:40:08 0 d-------- C:\Users\dayne\AppData\Roaming\Paltalk
2008-04-12 15:12:09 0 d-------- C:\Users\dayne\AppData\Roaming\WildTangent
2008-04-08 11:40:10 0 d-------- C:\Users\dayne\AppData\Roaming\Talkback
2008-04-08 11:39:25 0 d-------- C:\Users\dayne\AppData\Roaming\Mozilla
2008-04-08 00:27:09 0 d-------- C:\Program Files\Java
2008-04-02 18:18:46 0 d-------- C:\Program Files\Common Files\Logitech
2008-03-25 03:03:35 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-11 20:53:35 0 d-------- C:\Program Files\AIM
2008-03-11 20:31:25 0 d-------- C:\Program Files\AOD
2008-03-11 12:17:28 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-09 12:50:48 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-03 14:53:06 0 d-------- C:\Users\dayne\AppData\Roaming\Adobe
2008-03-02 17:36:50 0 --a------ C:\Windows\nsreg.dat


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{733716E1-76D2-4003-AC39-845281C0EF85}]
C:\Windows\system32\nsfB75E.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{90ee6848-d086-25fd-4b25-73d4ae6a5c38}]
04/10/2008 11:12 AM 329728 --a------ C:\Windows\system32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [09/05/2007 02:32 PM]
"RtHDVCpl"="RtHDVCpl.exe" [08/09/2007 10:26 PM C:\Windows\RtHDVCpl.exe]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [03/29/2007 01:39 PM]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [12/07/2006 07:49 PM]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [06/16/2007 12:01 AM]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [05/22/2007 07:32 PM]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [08/15/2007 06:31 PM]
"NDSTray.exe"="NDSTray.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 AM]
"MSServer"="C:\Windows\system32\vtUmJYss.dll" [04/14/2008 03:53 PM]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [02/01/2008 12:55 PM]
"spa_start"="C:\Windows\system32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll" [04/10/2008 11:12 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [03/15/2007 07:16 PM]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [01/10/2008 04:04 AM]
"cmds"="C:\Users\dayne\AppData\Local\Temp\xxyawxwV.dll,c" []
"MSServer"="C:\Users\dayne\AppData\Local\Temp\fccdATll.dll,#1" []
"Fast mix"="C:\ProgramData\SIXTH TWO TWO.rq6qp" [04/15/2008 04:31 AM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [10/04/2007 11:20 AM]
"BM4feffca8"="C:\Users\dayne\AppData\Local\Temp\mjwwbfds.dll,s" []
"MS Juan"="C:\Users\dayne\AppData\Local\Temp\esaekuiu.dll,run" []
"4cdccf34"="C:\Users\dayne\AppData\Local\Temp\fpsrlygi.dll,b" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DelayShred"="C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P2 /q C:\Users\dayne\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WA8LNGUE\TCODE_~2.SH!
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [4/15/2008 3:51:47 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{7CE67716-5803-4FB7-B344-0C7A17F93B5D}"= C:\Users\dayne\AppData\Local\Temp\fccdATll.dll [ ]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum
LocalServiceNoNetwork PLA DPS BFE mpssvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{73fdcf9e-a331-11dc-b768-001644735690}]
AutoRun\command- F:\LaunchU3.exe -a


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-04-16 16:12:16 ------------

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft® Windows Vista™ Home Basic (build 6000)
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 X2 Dual-Core Processor TK-53
Percentage of Memory in Use: 53%
Physical Memory (total/avail): 1917.44 MiB / 890.72 MiB
Pagefile Memory (total/avail): 4057.18 MiB / 2412.85 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1934.05 MiB

C: is Fixed (NTFS) - 110.32 GiB total, 75.15 GiB free.
D: is CDROM (No Media)
E: is Removable (FAT)
F: is CDROM (CDFS)

\\.\PHYSICALDRIVE0 - FUJITSU MHY2120BH ATA Device - 111.79 GiB - 2 partitions
\PARTITION0 - Unknown - 1500 MiB
\PARTITION1 (bootable) - Installable File System - 110.32 GiB - C:

\\.\PHYSICALDRIVE1 - SanDisk U3 Cruzer Micro USB Device - 980.53 MiB - 1 partition
\PARTITION0 (bootable) - Win95 w/Extended Int 13 - 981.4 MiB - E:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

FW: McAfee Personal Firewall v (McAfee)
AV: McAfee VirusScan v (McAfee)
AS: McAfee VirusScan v (McAfee)
AS: Spyware Doctor v5.5.0.204 (PC Tools)
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation) Disabled

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"="C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine"
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"="C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\dayne\AppData\Roaming
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=TOSHI
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\dayne
LOCALAPPDATA=C:\Users\dayne\AppData\Local
LOGONSERVER=\\TOSHI
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 104 Stepping 1, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=6801
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\dayne\AppData\Local\Temp
TMP=C:\Users\dayne\AppData\Local\Temp
USERDOMAIN=toshi
USERNAME=dayne
USERPROFILE=C:\Users\dayne
windir=C:\Windows


-- User Profiles ---------------------------------------------------------------

dayne
Mom
Leon (admin)
Guest (guest)


-- Add/Remove Programs ---------------------------------------------------------

--> "C:\Program Files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe" --u:{A644254B-92F6-4970-8635-AB0775371E72}
--> "C:\Program Files\TOSHIBA Games\Bejeweled 2 Deluxe\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\Blackhawk Striker 2\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\Diner Dash\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\FATE\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\Mah Jong Quest\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\Penguins!\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\Polar Bowler\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\Polar Golfer\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\Tradewinds\Uninstall.exe"
--> "C:\Program Files\TOSHIBA Games\Virtual Villagers - A New Home\Uninstall.exe"
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{622E6F16-0904-49B6-BBE1-4CC836314CCF}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{697AFC77-F318-4CD4-BF16-F50F4C1072DA}\setup.exe" -l0x9
Abassis Finance Manager 1.3 --> "C:\Program Files\Abassis Finance Manager\unins000.exe"
Activation Assistant for the 2007 Microsoft Office suites --> "C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe Flash Player ActiveX --> C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player 11 --> C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
AIM 6 --> C:\Program Files\AIM6\uninst.exe
Alarm Clock v1.0 --> "C:\Program Files\Alarm Clock\unins000.exe"
AvPropPlugin 1.0.0.1 --> C:\PROGRA~1\AVPROP~1\UNWISE.EXE C:\PROGRA~1\AVPROP~1\INSTALL.LOG
Bluetooth Stack for Windows by Toshiba --> MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Camfrog Video Chat 4.1 (remove only) --> "C:\Program Files\Camfrog\Camfrog Video Chat\uninstall.exe"
Catalyst Control Center - Branding --> MsiExec.exe /I{22543949-70E8-45D0-A938-F38143EB8BF8}
CD/DVD Drive Acoustic Silencer --> C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe -runfromtemp -l0x0009 -removeonly
CiD Help --> C:\PROGRA~2\FILEBO~1\Loadinside.exe -uninstall
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
COWON Media Center - jetAudio Basic --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\setup.exe" -l0x9 -removeonly
Drivers Install For Linksys Easylink Advisor --> MsiExec.exe /I{A1960A82-DB70-474D-A86B-FA74466103C6}
DVD MovieFactory for TOSHIBA --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}\setup.exe" -l0x9
Enhancement Browser Tools Nextads --> C:\Windows\system32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll-uninst.exe
EO Video 1.36 --> C:\Windows\iun6002.exe "C:\Program Files\EO Video\irunin.ini"
Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
HijackThis 2.0.2 --> "C:\Users\dayne\Desktop\HijackThis.exe" /uninstall
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Kaspersky Online Scanner --> C:\Windows\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
Linksys EasyLink Advisor 1.6 (0032) --> rundll32 C:\PROGRA~1\LINKSY~1\AUInst.dll,ExUninstall
Logitech QuickCam --> MsiExec.exe /X{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}
Macromedia Flash Player 8 --> MsiExec.exe /X{6815FCDD-401D-481E-BA88-31B4754C2B46}
McAfee SecurityCenter --> C:\Program Files\McAfee\MSC\mcuninst.exe
Memorex exPressit Label Design Studio --> C:\Windows\mvuninst\App1\mvuninst.exe "Memorex exPressit Label Design Studio"
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Home and Student 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007 --> MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (English) --> MsiExec.exe /X{95120000-00AF-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Works --> MsiExec.exe /I{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}
Mozilla Firefox (2.0.0.13) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
OpenOffice.org 2.4 --> MsiExec.exe /I{F87A8E11-02A4-4875-A3A5-5961081B0E4E}
PaltalkScene --> "C:\Windows\PaltalkScene\uninstall.exe" "/U:C:\Program Files\Paltalk Messenger\irunin.xml"
QuickBooks Financial Center --> MsiExec.exe /I{890EF3F8-742F-46BD-9E8E-084B3A1F4364}
QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista --> C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x9 -removeonly
REALTEK RTL8187B Wireless LAN Driver --> C:\Program Files\InstallShield Installation Information\{7095FD27-37F0-4750-9DE8-D37DC0043706}\Install.exe -uninst -l0x9
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x9 anything
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Excel 2007 (KB946974) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
Security Update for Office 2007 (KB947801) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
Security Update for Visio 2007 (KB947590) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
Spyware Doctor 5.5 --> C:\Program Files\Spyware Doctor\unins000.exe /LOG
Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
TOSHIBA Assist --> C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe -runfromtemp -l0x0009 -removeonly
TOSHIBA ConfigFree --> C:\Program Files\InstallShield Installation Information\{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}\setup.exe -runfromtemp -l0x0009 uninstall
TOSHIBA Disc Creator --> MsiExec.exe /X{5DA0E02F-970B-424B-BF41-513A5018E4C0}
TOSHIBA DVD PLAYER --> C:\Program Files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe -runfromtemp -l0x0009 -ADDREMOVE -removeonly
TOSHIBA Extended Tiles for Windows Mobility Center --> C:\Program Files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe -runfromtemp -l0x0409
TOSHIBA Games --> "C:\Program Files\TOSHIBA Games\Uninstall.exe"
TOSHIBA Hardware Setup --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BFC85CDC-BD7C-4FDD-9507-8D74B5A79404}\setup.exe" -l0x9
Toshiba Registration --> MsiExec.exe /I{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}
TOSHIBA SD Memory Utilities --> MsiExec.exe /X{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}
TOSHIBA Software Modem --> Tosmreg -U
TOSHIBA Software Upgrades --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{425A2BC2-AA64-4107-9C29-484245BBEA05}\setup.exe" -l0x9 -removeonly
TOSHIBA Speech System Applications --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE033C1F-443E-41EC-A0E2-559B539A4E4D}\Setup.exe" -l0x9
TOSHIBA Speech System SR Engine(U.S.) Version1.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{008D69EB-70FF-46AB-9C75-924620DF191A}\Setup.exe" -l0x9 UNINSTALL
TOSHIBA Speech System TTS Engine(U.S.) Version1.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3FBF6F99-8EC6-41B4-8527-0A32241B5496}\Setup.exe" -l0x9
TOSHIBA Supervisor Password --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2BDF38E0-1A7F-4220-B4B7-118DD45E5E13}\setup.exe" -l0x9
TOSHIBA Value Added Package --> C:\Program Files\InstallShield Installation Information\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\setup.exe -runfromtemp -l0x0409
Update for Office 2007 (KB934528) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {2B939677-2FFD-48F6-9075-7BF48CB87C80}
Update for Office 2007 (KB946691) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Office System 2007 Setup (KB929722) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {D8E9BEBD-655F-467D-8176-CA9959C140A3}
Winbond CIR Device Drivers --> MsiExec.exe /I{755F77D1-717E-4D7D-BF21-D3EB63906365}
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Media Encoder 9 Series --> msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Encoder 9 Series --> MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Yahoo! Internet Mail --> C:\Windows\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG


-- Application Event Log -------------------------------------------------------

Event Record #/Type4805 / Error
Event Submitted/Written: 04/16/2008 10:46:43 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application iexplore.exe, version 7.0.6000.16643, time stamp 0x47bce1b0, faulting module mjwwbfds.dll_unloaded, version 0.0.0.0, time stamp 0x41a9837a, exception code 0xc0000005, fault offset 0x00501568,
process id 0x924, application start time 0xiexplore.exe0.

Event Record #/Type4803 / Error
Event Submitted/Written: 04/16/2008 10:46:12 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application firefox.exe, version 1.8.20080.31114, time stamp 0x47d7134a, faulting module mjwwbfds.dll, version 0.0.0.0, time stamp 0x41a9837a, exception code 0xc0000005, fault offset 0x00001568,
process id 0xc40, application start time 0xfirefox.exe0.

Event Record #/Type4797 / Error
Event Submitted/Written: 04/16/2008 10:44:35 AM
Event ID/Source: 5007 / WerSvc
Event Description:
The target file for the Windows Feedback Platform (a DLL file containing the list of problems on this computer that require additional data collection for diagnosis) could not be parsed. The error code was 8014FFF9.

Event Record #/Type4796 / Success
Event Submitted/Written: 04/16/2008 10:44:31 AM
Event ID/Source: 5617 / WinMgmt
Event Description:


Event Record #/Type4795 / Success
Event Submitted/Written: 04/16/2008 10:44:22 AM
Event ID/Source: 5615 / WinMgmt
Event Description:




-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type31207 / Warning
Event Submitted/Written: 04/16/2008 10:50:30 AM
Event ID/Source: 4 / Client Side Rendering Spooler
Event Description:
The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.

Event Record #/Type31206 / Warning
Event Submitted/Written: 04/16/2008 10:50:30 AM
Event ID/Source: 4 / Client Side Rendering Spooler
Event Description:
The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.

Event Record #/Type31205 / Warning
Event Submitted/Written: 04/16/2008 10:49:13 AM
Event ID/Source: 4 / Client Side Rendering Spooler
Event Description:
The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.

Event Record #/Type31204 / Warning
Event Submitted/Written: 04/16/2008 10:49:13 AM
Event ID/Source: 4 / Client Side Rendering Spooler
Event Description:
The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key S-1-5-18\Printers\Connections. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.

Event Record #/Type31136 / Error
Event Submitted/Written: 04/16/2008 10:44:36 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Parallel port driver%%1058



-- End of Deckard's System Scanner: finished at 2008-04-16 16:12:16 ------------

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 16, 2008 4:03:43 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/04/2008
Kaspersky Anti-Virus database records: 710904
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 120626
Number of viruses found: 4
Number of infected objects: 32
Number of suspicious objects: 0
Duration of the scan process: 01:37:45

Infected Object Name / Virus Name / Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\ProgramData\McAfee\MNA\NAData Object is locked skipped
C:\ProgramData\McAfee\MPF\data\log.edb Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{1A94CE64-FDA5-49FE-9314-B367137E3D4B}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{8BCDE3AE-7DB7-4AAD-AAF0-68DE01CA3EA7}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\McUsers.dat Object is locked skipped
C:\ProgramData\McAfee\VirusScan\Data\TFRFA26.tmp Object is locked skipped
C:\ProgramData\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.116.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.116.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010008.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000B.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010012.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010015.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001B.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001C.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001D.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010023.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010023.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010023.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy241.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf8A73.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf8AC2.tmp Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\dayne\AppData\Local\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012008041620080417\index.dat Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\UsrClass.dat{73fdcf76-a331-11dc-b768-001644735690}.TM.blf Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\UsrClass.dat{73fdcf76-a331-11dc-b768-001644735690}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows\UsrClass.dat{73fdcf76-a331-11dc-b768-001644735690}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\dayne\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\dayne\AppData\Local\Temp\efcBqpOg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\fccdATll.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\lJawXPhG.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\mlJBRLed.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\nnnliGaX.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\nsi5741.tmp\bann.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.TrafficSol.t skipped
C:\Users\dayne\AppData\Local\Temp\nsi5741.tmp\bann.exe/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.t skipped
C:\Users\dayne\AppData\Local\Temp\nsi5741.tmp\bann.exe NSIS: infected - 2 skipped
C:\Users\dayne\AppData\Local\Temp\nsi5D0B.tmp\bann.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.TrafficSol.t skipped
C:\Users\dayne\AppData\Local\Temp\nsi5D0B.tmp\bann.exe/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.t skipped
C:\Users\dayne\AppData\Local\Temp\nsi5D0B.tmp\bann.exe NSIS: infected - 2 skipped
C:\Users\dayne\AppData\Local\Temp\Temp1_[Full] archicad 11 crack with Bonus.zip\setup.exe/data0009/stream/data0004 Infected: not-a-virus:AdWare.Win32.TrafficSol.t skipped
C:\Users\dayne\AppData\Local\Temp\Temp1_[Full] archicad 11 crack with Bonus.zip\setup.exe/data0009/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.t skipped
C:\Users\dayne\AppData\Local\Temp\Temp1_[Full] archicad 11 crack with Bonus.zip\setup.exe/data0009 Infected: not-a-virus:AdWare.Win32.TrafficSol.t skipped
C:\Users\dayne\AppData\Local\Temp\Temp1_[Full] archicad 11 crack with Bonus.zip\setup.exe NSIS: infected - 3 skipped
C:\Users\dayne\AppData\Local\Temp\tmp00014642 Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\tmp0001bac6 Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\tmp0003e906 Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\tmp00297a8c Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\tmp0078dce8 Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\tmp0091c39f Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\vbnojyoj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.okj skipped
C:\Users\dayne\AppData\Local\Temp\vtUmKBSL.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\waqeklff.dll Infected: Trojan.Win32.KillAV.rf skipped
C:\Users\dayne\AppData\Local\Temp\wvULdDTJ.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\dayne\AppData\Local\Temp\~DF6805.tmp Object is locked skipped
C:\Users\dayne\AppData\Roaming\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\gdql_lsa_LinksysAgent.log Object is locked skipped
C:\Users\dayne\AppData\Roaming\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\glog.log Object is locked skipped
C:\Users\dayne\AppData\Roaming\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\LinksysAgent.log Object is locked skipped
C:\Users\dayne\AppData\Roaming\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\LinksysAgent_GTActions.log Object is locked skipped
C:\Users\dayne\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\dayne\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat Object is locked skipped
C:\Users\dayne\NTUSER.DAT Object is locked skipped
C:\Users\dayne\ntuser.dat.LOG1 Object is locked skipped
C:\Users\dayne\ntuser.dat.LOG2 Object is locked skipped
C:\Users\dayne\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf Object is locked skipped
C:\Users\dayne\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\dayne\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Guest\AppData\Local\Temp\byXRjkHb.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\Guest\AppData\Local\Temp\fCRIbCtQ.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\Guest\AppData\Local\Temp\tmp00013ed3 Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\Guest\AppData\Local\Temp\tmp004b116f Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\Guest\AppData\Local\Temp\tuvUMdBQ.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\Mom\AppData\Local\Temp\pmnlmjJd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Users\Public\Documents\Config\desktop2.idf Object is locked skipped
C:\Users\Public\Documents\Fonts\SwUniNew.tff Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{11177e9a-0106-11dd-92de-806e6f6e6963}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{11177e9a-0106-11dd-92de-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{11177e9a-0106-11dd-92de-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{11177e9e-0106-11dd-92de-001644735690}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{11177e9e-0106-11dd-92de-001644735690}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{11177e9e-0106-11dd-92de-001644735690}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\SoftwareDistribution\EventCache\{56576E66-84E2-41C0-83A7-1E0D7CD8021E}.bin Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\drivers\core.cache.dsk Object is locked skipped
C:\Windows\System32\drivers\mrxsmbb.sys Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\vtUmJYss.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mde skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.003 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\ACEEventLog.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Temp\Cookies\index.dat Object is locked skipped
C:\Windows\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Windows\Temp\mcafee_qk4rcHgonsQbRql Object is locked skipped
C:\Windows\Temp\mcafee_rOAG0zMMeIg9ivv Object is locked skipped
C:\Windows\Temp\mcmsc_lPf9pZvf63BguUt Object is locked skipped
C:\Windows\Temp\mcmsc_lvYtrJNH9yU0bxz Object is locked skipped
C:\Windows\Temp\mcmsc_QdrIf5fphEv25L7 Object is locked skipped
C:\Windows\Temp\mcmsc_T71sT4T2YjeJgFA Object is locked skipped
C:\Windows\Temp\mcmsc_VmAvdb8P89smZvU Object is locked skipped
C:\Windows\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Windows\Temp\~DF1141.tmp Object is locked skipped
C:\Windows\Temp\~DF13D4.tmp Object is locked skipped
C:\Windows\Temp\~DF1B2.tmp Object is locked skipped
C:\Windows\Temp\~DF1C7C.tmp Object is locked skipped
C:\Windows\Temp\~DF300E.tmp Object is locked skipped
C:\Windows\Temp\~DF4C7D.tmp Object is locked skipped
C:\Windows\Temp\~DF6598.tmp Object is locked skipped
C:\Windows\Temp\~DF8DCC.tmp Object is locked skipped
C:\Windows\Temp\~DF944C.tmp Object is locked skipped
C:\Windows\Temp\~DF9BE6.tmp Object is locked skipped
C:\Windows\Temp\~DFAE0E.tmp Object is locked skipped
C:\Windows\Temp\~DFBB57.tmp Object is locked skipped
C:\Windows\Temp\~DFDB13.tmp Object is locked skipped
C:\Windows\Temp\~DFEE1A.tmp Object is locked skipped
C:\Windows\Temp\~DFF99C.tmp Object is locked skipped
C:\Windows\Temp\~DFFA6E.tmp Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped

Scan process completed.

BC AdBot (Login to Remove)

 


m

#2 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:08:39 PM

Posted 18 April 2008 - 03:58 AM

Hello L. Soule and welcome to BleepingComputer,

1. * Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Under Browsing History, click Delete.
  • Click Delete Files, Delete cookies and Delete history
  • Click Close below.
* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu..
  • Click the Clear now button below.. A new window will popup what to clear.
  • Select all and click the Clear button again.
  • Click OK to close the Options window
* Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.
2. Please download Malwarebytes' Anti-Malware from Here or Here

Doubleclick mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply along with a fresh HijackThis log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

3. Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.
The Windows Recovery Console will allow you to boot up into a special recovery mode, in case your computer has a problem after an attempted removal of malware. This allows us to help you .

In the event you already have Combofix, delete your current version and download the latest version as described in the tutorial.
It must be saved directly to your desktop.


Note: Make sure not to click ComboFix's window while it's running. That may cause it to stall or freeze.

Please post the log from ComboFix (can also be found as C:\ComboFix.txt) in your next reply. :thumbsup:

If you have any questions along the way, STOP and ask them before proceeding !!

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#3 L. Soule

L. Soule
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Taunton, MA, USA
  • Local time:02:39 PM

Posted 19 April 2008 - 12:27 PM

Malwarebytes' Anti-Malware 1.11
Database version: 599

Scan type: Quick Scan
Objects scanned: 34027
Time elapsed: 6 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 8
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{733716e1-76d2-4003-ac39-845281c0ef85} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{733716e1-76d2-4003-ac39-845281c0ef85} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\{59a40ac9-e67d-4155-b31d-4b7330fcd2d6} (Adware.PurityScan) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MS Juan (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cmds (Trojan.Agent) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM4feffca8 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\www.host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outerinfo (Malware.Trace) -> Quarantined and deleted successfully.

Files Infected:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outerinfo\Uninstall.lnk (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\System32\vtUmJYss.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\dayne\AppData\Local\Temp\khfeBSif.dll (Trojan.Agent) -> Delete on reboot.
C:\Users\dayne\AppData\Local\Temp\xxyawxwV.dll (Trojan.Agent) -> Delete on reboot.
C:\Windows\System32\drivers\core.cache.dsk (Malware.Trace) -> Delete on reboot.

--

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:29 PM, on 4/19/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Users\dayne\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kaspersky.com/virusscanner
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: nextads browser optimizer - {90ee6848-d086-25fd-4b25-73d4ae6a5c38} - C:\Windows\system32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P2 /q C:\Users\dayne\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WA8LNGUE\TCODE_~2.SH! (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P2 /q C:\Users\dayne\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WA8LNGUE\TCODE_~2.SH! (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 9147 bytes

--

ComboFix 08-04-18.3 - dayne 2008-04-19 12:55:17.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.1310 [GMT -4:00]
Running from: C:\Users\dayne\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\icroso~1.net
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\Users\dayne\Documents\MBOLS~1
C:\Users\dayne\Documents\MBOLS~1\??mbols\
C:\Windows\system32\bszip.dll
C:\Windows\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-03-19 to 2008-04-19 )))))))))))))))))))))))))))))))
.

2008-04-19 13:04 . 2008-04-19 13:04 <DIR> d-------- C:\Temp\tn3
2008-04-19 11:41 . 2008-04-19 12:43 <DIR> d-------- C:\Users\dayne\AppData\Roaming\OpenOffice.org2
2008-04-19 11:23 . 2008-04-19 11:23 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Malwarebytes
2008-04-19 11:23 . 2008-04-19 11:23 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-04-19 11:23 . 2008-04-19 11:23 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-04-19 11:23 . 2008-04-19 11:23 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-19 11:03 . 2008-04-19 11:03 100 --a------ C:\Windows\System32\ikhcore.cfg
2008-04-16 16:04 . 2008-04-16 16:04 <DIR> d-------- C:\Deckard
2008-04-16 11:56 . 2008-04-16 11:56 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-04-16 11:56 . 2008-04-16 11:56 <DIR> d-------- C:\Users\All Users\Kaspersky Lab
2008-04-16 11:56 . 2008-04-16 11:56 <DIR> d-------- C:\ProgramData\Kaspersky Lab
2008-04-15 13:07 . 2008-04-15 13:07 <DIR> d-------- C:\Users\dayne\AppData\Roaming\PC Tools
2008-04-15 13:07 . 2008-04-15 14:07 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-04-15 13:07 . 2007-12-10 14:53 81,288 --a------ C:\Windows\System32\drivers\iksyssec.sys
2008-04-15 13:07 . 2007-12-10 14:53 66,952 --a------ C:\Windows\System32\drivers\iksysflt.sys
2008-04-15 13:07 . 2008-02-01 12:55 42,376 --a------ C:\Windows\System32\drivers\ikfilesec.sys
2008-04-15 13:07 . 2007-12-10 14:53 29,576 --a------ C:\Windows\System32\drivers\kcom.sys
2008-04-15 09:25 . 2008-04-19 12:58 5,112 --a------ C:\Windows\System32\Config.MPF
2008-04-15 09:18 . 2006-03-03 11:07 143,360 --a------ C:\Windows\System32\dunzip32.dll
2008-04-15 09:14 . 2008-02-06 09:51 171,400 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-04-15 09:14 . 2007-03-02 14:17 120,360 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-04-15 09:14 . 2007-06-25 14:54 71,496 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-04-15 09:14 . 2007-06-25 10:57 37,480 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-04-15 09:14 . 2007-06-25 10:57 34,184 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-04-15 09:14 . 2007-06-25 10:57 32,008 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-04-15 09:13 . 2008-04-15 09:13 <DIR> d-------- C:\Program Files\McAfee.com
2008-04-15 09:13 . 2008-04-15 09:23 <DIR> d-------- C:\Program Files\McAfee
2008-04-15 09:13 . 2008-04-15 09:18 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-04-15 03:51 . 2008-04-19 11:11 <DIR> d-------- C:\Users\All Users\Google Updater
2008-04-15 03:51 . 2008-04-19 11:11 <DIR> d-------- C:\ProgramData\Google Updater
2008-04-14 21:12 . 2008-04-14 21:12 <DIR> d-------- C:\Users\Mom\AppData\Roaming\Paltalk
2008-04-14 15:57 . 2008-04-15 10:50 <DIR> d--hs---- C:\Users\dayne\'
2008-04-14 15:54 . 2008-04-19 11:01 167,545 --a------ C:\Windows\System32\drivers\core.cache.dsk
2008-04-14 15:54 . 2008-04-14 15:54 86,144 --a------ C:\Windows\System32\drivers\mrxsmbb.sys
2008-04-14 15:53 . 2008-04-14 21:02 <DIR> d--hs---- C:\Windows\ZGF5bmU
2008-04-14 15:53 . 2008-04-14 15:53 <DIR> d-------- C:\Windows\System32\vFi
2008-04-14 15:53 . 2008-04-15 12:45 <DIR> d-------- C:\Windows\System32\pinz1
2008-04-14 15:53 . 2008-04-14 15:53 <DIR> d-------- C:\Windows\System32\IDE2
2008-04-14 15:53 . 2008-04-15 12:44 <DIR> d-------- C:\Windows\System32\ExTmp
2008-04-14 15:53 . 2008-04-15 09:33 <DIR> d-------- C:\Windows\System32\bharebio05
2008-04-14 15:53 . 2008-04-14 15:53 <DIR> d-------- C:\Temp\wdlw14
2008-04-14 15:53 . 2008-04-19 13:04 <DIR> d-------- C:\Temp
2008-04-14 15:53 . 2008-04-15 04:10 63,839 --a------ C:\Windows\System32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll-uninst.exe
2008-04-14 15:53 . 2008-04-14 15:53 267 --a------ C:\Windows\System32\6164.bat
2008-04-13 14:54 . 2008-04-13 14:54 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Camfrog
2008-04-13 14:54 . 2008-04-13 14:54 <DIR> d-------- C:\Program Files\Camfrog
2008-04-13 14:38 . 2008-04-13 14:38 <DIR> d-------- C:\Windows\PaltalkScene
2008-04-13 14:38 . 2008-04-13 14:40 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Paltalk
2008-04-13 14:38 . 2008-04-13 14:38 <DIR> d-------- C:\Program Files\Paltalk Messenger
2008-04-13 00:21 . 2008-04-13 00:21 <DIR> d-------- C:\Program Files\AvPropPlugin
2008-04-12 23:54 . 2008-04-12 23:54 <DIR> d-------- C:\Users\All Users\Logitech
2008-04-12 23:54 . 2008-04-12 23:59 <DIR> d-------- C:\Users\All Users\Logishrd
2008-04-12 23:54 . 2008-04-12 23:54 <DIR> d-------- C:\ProgramData\Logitech
2008-04-12 23:54 . 2008-04-12 23:59 <DIR> d-------- C:\ProgramData\Logishrd
2008-04-12 23:54 . 2008-04-12 23:54 <DIR> d-------- C:\Program Files\Logitech
2008-04-12 23:52 . 2008-04-12 23:55 <DIR> d-------- C:\Program Files\Common Files\logishrd
2008-04-12 21:00 . 2008-04-12 21:00 <DIR> d-------- C:\Users\All Users\Admin Inter 1 Mags
2008-04-12 21:00 . 2008-04-12 21:00 <DIR> d-------- C:\ProgramData\Admin Inter 1 Mags
2008-04-12 20:59 . 2008-04-12 21:00 <DIR> d-------- C:\Users\All Users\File bold bib
2008-04-12 20:59 . 2008-04-12 21:00 <DIR> d-------- C:\ProgramData\File bold bib
2008-04-12 20:48 . 2008-04-12 20:48 <DIR> d-------- C:\Windows\System32\Adobe
2008-04-12 15:12 . 2008-04-12 15:12 <DIR> d-------- C:\Users\dayne\AppData\Roaming\WildTangent
2008-04-11 23:43 . 2008-04-14 15:38 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Yahoo!
2008-04-10 11:12 . 2008-04-10 11:12 329,728 --a------ C:\Windows\System32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll
2008-04-08 11:40 . 2008-04-08 11:40 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Talkback
2008-04-08 00:32 . 2008-04-08 00:32 <DIR> d-------- C:\Users\Leon\AppData\Roaming\OpenOffice.org2
2008-04-08 00:27 . 2008-04-08 01:04 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-07 17:09 . 2006-05-31 15:25 25,088 --a------ C:\Windows\System32\msxml3a.dll
2008-04-06 14:09 . 2008-04-06 14:09 <DIR> d-------- C:\Users\Leon\AppData\Roaming\Template
2008-04-06 14:09 . 2008-04-06 14:20 540 --a------ C:\Users\Leon\AppData\Roaming\wklnhst.dat
2008-04-05 22:17 . 2008-04-05 22:17 <DIR> d-------- C:\Users\Leon\AppData\Roaming\U3
2008-04-05 02:15 . 2008-04-14 15:38 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-04 20:12 . 2008-04-05 02:16 <DIR> d-------- C:\Users\Leon\AppData\Roaming\Apple Computer
2008-04-04 20:11 . 2008-04-04 20:12 54,156 --ah----- C:\Windows\QTFont.qfn
2008-04-04 20:11 . 2008-04-04 20:12 1,409 --a------ C:\Windows\QTFont.for
2008-04-04 20:09 . 2008-04-05 02:19 <DIR> d-------- C:\Users\All Users\Apple Computer
2008-04-04 20:09 . 2008-04-05 02:19 <DIR> d-------- C:\ProgramData\Apple Computer
2008-04-04 20:09 . 2008-04-04 20:09 <DIR> d-------- C:\Program Files\QuickTime
2008-04-03 17:40 . 2008-04-03 17:40 <DIR> d-------- C:\Users\Leon\AppData\Roaming\COWON
2008-04-03 17:35 . 2008-04-03 18:39 <DIR> d-------- C:\Users\Leon\Shared
2008-04-03 17:35 . 2008-04-03 19:32 <DIR> d-------- C:\Users\Leon\Incomplete
2008-04-03 17:35 . 2008-04-03 17:40 <DIR> d-------- C:\Users\Leon\AppData\Roaming\LimeWire
2008-04-03 14:10 . 2008-04-03 14:10 <DIR> d-------- C:\Users\Leon\AppData\Roaming\Talkback
2008-04-03 13:57 . 2008-04-03 13:57 <DIR> d-------- C:\Users\Leon\AppData\Roaming\acccore
2008-04-03 13:53 . 2008-04-08 01:11 <DIR> dr------- C:\Users\Leon\Videos
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> dr------- C:\Users\Leon\Searches
2008-04-03 13:53 . 2008-04-03 22:51 <DIR> dr------- C:\Users\Leon\Saved Games
2008-04-03 13:53 . 2008-04-08 01:13 <DIR> dr------- C:\Users\Leon\Pictures
2008-04-03 13:53 . 2008-04-08 01:12 <DIR> dr------- C:\Users\Leon\Music
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> dr------- C:\Users\Leon\Links
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> dr------- C:\Users\Leon\Downloads
2008-04-03 13:53 . 2008-04-08 01:10 <DIR> dr------- C:\Users\Leon\Documents
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> dr------- C:\Users\Leon\Contacts
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> d-------- C:\Users\Leon\AppData\Roaming\Gtek
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> d--h----- C:\Users\Leon\AppData
2008-04-03 13:53 . 2008-04-08 01:13 <DIR> d-------- C:\Users\Leon
2008-04-03 13:53 . 2008-04-03 19:33 524,288 --ahs---- C:\Users\Leon\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms
2008-04-03 13:53 . 2008-04-03 19:33 524,288 --ahs---- C:\Users\Leon\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
2008-04-03 13:53 . 2008-04-19 12:55 262,144 --ah----- C:\Users\Leon\ntuser.dat.LOG1
2008-04-03 13:53 . 2008-04-03 19:33 65,536 --ahs---- C:\Users\Leon\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
2008-04-03 13:53 . 2008-04-03 13:53 0 --ah----- C:\Users\Leon\ntuser.dat.LOG2
2008-04-02 18:42 . 2008-04-02 20:59 524,288 --ahs---- C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{11177e9e-0106-11dd-92de-001644735690}.TMContainer00000000000000000002.regtrans-ms
2008-04-02 18:42 . 2008-04-02 20:59 524,288 --ahs---- C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{11177e9e-0106-11dd-92de-001644735690}.TMContainer00000000000000000001.regtrans-ms
2008-04-02 18:42 . 2008-04-02 20:59 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{11177e9a-0106-11dd-92de-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms
2008-04-02 18:42 . 2008-04-02 20:59 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{11177e9a-0106-11dd-92de-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
2008-04-02 18:42 . 2008-04-02 20:59 65,536 --ahs---- C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{11177e9e-0106-11dd-92de-001644735690}.TM.blf
2008-04-02 18:42 . 2008-04-02 20:59 65,536 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{11177e9a-0106-11dd-92de-806e6f6e6963}.TM.blf
2008-04-02 17:59 . 2008-04-02 17:59 2,560 --a------ C:\Windows\_MSRSTRT.EXE
2008-03-29 12:00 . 2008-04-15 09:22 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-29 11:59 . 2008-04-13 18:02 <DIR> d-------- C:\Users\All Users\Symantec
2008-03-29 11:59 . 2008-04-13 18:02 <DIR> d-------- C:\ProgramData\Symantec
2008-03-29 11:57 . 2008-04-19 11:25 <DIR> d-a------ C:\Users\All Users\TEMP
2008-03-29 11:57 . 2008-04-19 11:25 <DIR> d-a------ C:\ProgramData\TEMP
2008-03-29 03:17 . 2008-03-29 03:17 <DIR> d-------- C:\Users\All Users\WLInstaller
2008-03-29 03:17 . 2008-03-29 03:17 <DIR> d-------- C:\ProgramData\WLInstaller
2008-03-29 03:17 . 2008-03-29 03:17 <DIR> d-------- C:\Program Files\Windows Live
2008-03-29 03:17 . 2008-03-29 03:19 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\Windows\System32\QuickTime.qts
2008-03-28 03:24 . 2008-03-28 03:24 <DIR> d-------- C:\Users\All Users\Azureus
2008-03-28 03:24 . 2008-03-28 03:24 <DIR> d-------- C:\ProgramData\Azureus
2008-03-24 23:49 . 2008-03-24 23:49 <DIR> d-------- C:\Program Files\Bonjour
2008-03-24 23:47 . 2008-03-24 23:47 <DIR> d-------- C:\Users\All Users\Apple
2008-03-24 23:47 . 2008-03-24 23:47 <DIR> d-------- C:\ProgramData\Apple
2008-03-23 21:11 . 2008-03-23 21:11 <DIR> d-------- C:\Program Files\EO Video

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 16:51 --------- d-----w C:\Users\dayne\AppData\Roaming\U3
2008-04-15 13:23 --------- d-----w C:\ProgramData\McAfee
2008-04-15 07:51 --------- d-----w C:\Program Files\Google
2008-04-14 20:06 --------- d-----w C:\Users\dayne\AppData\Roaming\LimeWire
2008-04-14 20:05 --------- d-----w C:\Program Files\LimeWire
2008-04-14 19:38 --------- d-----w C:\ProgramData\Yahoo!
2008-04-14 19:38 --------- d-----w C:\ProgramData\Viewpoint
2008-04-14 19:37 --------- d-----w C:\Users\dayne\AppData\Roaming\MP3Rocket
2008-04-12 19:12 --------- d-----w C:\ProgramData\WildTangent
2008-04-09 11:06 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-08 04:27 --------- d-----w C:\Program Files\Java
2008-04-02 22:18 --------- d-----w C:\Program Files\Common Files\Logitech
2008-04-01 14:36 --------- d-----w C:\Users\Mom\AppData\Roaming\OpenOffice.org2
2008-03-25 07:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-25 07:03 --------- d-----w C:\ProgramData\Napster
2008-03-17 22:21 --------- d-----w C:\Users\Mom\AppData\Roaming\acccore
2008-03-15 14:30 --------- d-----w C:\Users\Guest\AppData\Roaming\OpenOffice.org2
2008-03-12 00:53 --------- d-----w C:\Program Files\AIM
2008-03-12 00:31 --------- d-----w C:\Program Files\AOD
2008-03-11 16:17 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-09 16:50 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-05 14:44 --------- d-----w C:\Users\Mom\AppData\Roaming\Talkback
2008-03-05 14:41 --------- d-----w C:\Users\Mom\AppData\Roaming\Gtek
2008-03-05 14:41 --------- d-----w C:\Users\Mom\AppData\Roaming\ATI
2008-03-03 18:38 --------- d-----w C:\Users\Guest\AppData\Roaming\Talkback
2008-03-03 08:16 --------- d-----w C:\ProgramData\ArcSoft
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-21 02:03 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-02-17 16:32 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-17 16:30 613,888 ----a-w C:\Windows\System32\wpd_ci.dll
2008-02-17 16:30 224,824 ----a-w C:\Windows\System32\clfs.sys
2008-02-17 16:30 221,696 ----a-w C:\Windows\System32\umpnpmgr.dll
2008-02-17 16:30 19,456 ----a-w C:\Windows\System32\cfgmgr32.dll
2008-02-17 16:30 101,888 ----a-w C:\Windows\System32\drvinst.exe
2008-02-17 16:29 905,400 ----a-w C:\Windows\System32\winresume.exe
2008-02-17 16:29 595,456 ----a-w C:\Windows\System32\schedsvc.dll
2008-02-17 16:29 558,080 ----a-w C:\Windows\System32\oleaut32.dll
2008-02-17 16:29 39,424 ----a-w C:\Windows\System32\lodctr.exe
2008-02-17 16:29 35,328 ----a-w C:\Windows\System32\dispci.dll
2008-02-17 16:29 32,256 ----a-w C:\Windows\System32\unlodctr.exe
2008-02-17 16:29 260,096 ----a-w C:\Windows\System32\dpx.dll
2008-02-17 16:29 23,552 ----a-w C:\Windows\System32\nshhttp.dll
2008-02-17 16:29 17,408 ----a-w C:\Windows\System32\prflbmsg.dll
2008-02-17 16:29 12,800 ----a-w C:\Windows\System32\batt.dll
2008-02-17 16:29 115,200 ----a-w C:\Windows\System32\loadperf.dll
2008-02-17 16:29 1,585,664 ----a-w C:\Windows\System32\setupapi.dll
2008-02-17 16:27 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-17 16:27 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-17 16:27 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
2007-12-05 17:15 0 ----a-w C:\Users\dayne\AppData\Roaming\wklnhst.dat
2006-11-02 12:48 174 --sha-w C:\Program Files\desktop.ini
2007-12-25 22:16 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-12-25 22:16 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-12-25 22:16 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{90ee6848-d086-25fd-4b25-73d4ae6a5c38}]
2008-04-10 11:12 329728 --a------ C:\Windows\system32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 19:16 454784]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 04:04 1232896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-05 14:32 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-09 22:26 4702208 C:\Windows\RtHDVCpl.exe]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 13:39 411192]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [2006-12-07 19:49 55416]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 00:01 448080]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 19:32 538744]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-08-15 18:31 102400]
"NDSTray.exe"="NDSTray.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DelayShred"="C:\Program Files\McAfee\MSHR\ShrCL.exe" [2007-01-17 18:02 95784]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4cdccf34]
C:\Users\dayne\AppData\Local\Temp\fpsrlygi.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fast mix]
--a------ 2008-04-15 04:31 262160 C:\ProgramData\SIXTH TWO TWO.rq6qp

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3B2AE162-5B9E-4266-8C2E-6799D53935AE}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{15337CF1-CCDD-4FF3-AD97-082E86621E93}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4AD4B5CC-4642-4046-97F3-53262E99A638}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{53EAA5F8-9CA0-4B7C-A093-665A1DBE2031}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{8062FEC8-BF1E-46F4-B4B9-0E10E0793FA0}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{9AEFB83C-FC67-45FF-BFBC-B074903CE7E7}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{325A9B89-691D-4449-ACF3-27E97155A173}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{BBA9C5D3-275F-43D2-B80A-A3615E7A6D25}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"{452B22EC-D64C-4E89-80EC-2CCFF12C0215}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{9856E870-5CCB-4952-9EA8-F16906F37967}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{73740713-B1B5-42C9-9991-C7DEE78112BD}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{95DF761D-C480-440B-B9ED-D0B687EAA98D}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{7A67B89F-BB78-4556-86E2-1EAA42529E6C}C:\\program files\\aim6\\aim6.exe"= UDP:C:\program files\aim6\aim6.exe:AIM
"UDP Query User{4D8DFEBF-D20C-413A-A877-A1D103ADC515}C:\\program files\\aim6\\aim6.exe"= TCP:C:\program files\aim6\aim6.exe:AIM
"TCP Query User{9DAFAFA2-0CDC-42DA-A0FB-DA95BC24571A}C:\\program files\\aim\\aim.exe"= UDP:C:\program files\aim\aim.exe:AOL Instant Messenger
"UDP Query User{DB1ADE73-6AB5-4896-B9A7-08F96BBEE140}C:\\program files\\aim\\aim.exe"= TCP:C:\program files\aim\aim.exe:AOL Instant Messenger
"TCP Query User{DEB8AE8F-FEE7-4293-B3FD-93741043C67A}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{E6DFDAAF-D8EF-4720-83CC-84410550C9B9}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"{6F8F2FD5-A3C5-42A0-A3AA-BE2502FAE24A}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{10AC395B-62C5-481C-A2AC-FBD67BA206CC}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{1BD9F629-41E4-49E9-95AE-71CCE0279E16}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{27B0DE0B-C6DD-4055-A54E-3559084A00D4}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"TCP Query User{78C094CE-9CFE-4D18-8F98-64F0AEDF8AA6}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{085A63E3-BD38-490C-B1B0-4C60994BEEDF}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"TCP Query User{3F30B3BA-0CF4-4618-A389-AF52F082D883}C:\\program files\\bitdownload\\bitdownload.exe"= UDP:C:\program files\bitdownload\bitdownload.exe:BitDownload
"UDP Query User{12EFE342-4F2B-44ED-9ACD-381791DA232D}C:\\program files\\bitdownload\\bitdownload.exe"= TCP:C:\program files\bitdownload\bitdownload.exe:BitDownload
"TCP Query User{3154CC9A-71E9-4CD6-986B-C994E2EF2BA0}C:\\program files\\paltalk messenger\\paltalk.exe"= UDP:C:\program files\paltalk messenger\paltalk.exe:PaltalkScene
"UDP Query User{A7BE98FF-65EC-46A1-8DC3-71DC60850BD0}C:\\program files\\paltalk messenger\\paltalk.exe"= TCP:C:\program files\paltalk messenger\paltalk.exe:PaltalkScene
"{CD757239-E883-46C1-8475-7BC9E2E32736}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger

R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 14:23]
R0 tos_sps32;TOSHIBA tos_sps32 Service;C:\Windows\system32\DRIVERS\tos_sps32.sys [2007-08-01 17:37]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-28 02:36]
R3 FwLnk;FwLnk Driver;C:\Windows\system32\DRIVERS\FwLnk.sys [2006-11-20 02:11]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8187B.sys [2007-06-01 16:07]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 14:50]
S3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2006-11-02 03:30]
S3 tosrfec;Bluetooth ACPI;C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 19:32]
S3 winbondcir;Winbond IR Transceiver;C:\Windows\system32\DRIVERS\winbondcir.sys [2007-03-28 10:51]
S4 KR10I;KR10I;C:\Windows\system32\drivers\kr10i.sys [2006-11-09 02:32]
S4 KR10N;KR10N;C:\Windows\system32\drivers\kr10n.sys [2006-11-09 02:31]
S4 KR3NPXP;KR3NPXP;C:\Windows\system32\drivers\kr3npxp.sys [2006-09-27 08:06]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

.
Contents of the 'Scheduled Tasks' folder
"2008-04-15 13:22:50 C:\Windows\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-04-15 13:22:50 C:\Windows\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-04-19 17:05:21 C:\Windows\Tasks\User_Feed_Synchronization-{66F1B511-026D-4EC3-B6B7-E13E4509186D}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-19 13:04:22
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\agrsmsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\COMMON~1\McAfee\RedirSvc\RedirSvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Toshiba\IVP\ISM\pinger.exe
C:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\System32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Windows\System32\wbem\WMIADAP.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-04-19 13:07:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-19 17:07:21

Pre-Run: 80,651,087,872 bytes free
Post-Run: 80,648,269,824 bytes free

370 --- E O F --- 2008-04-13 17:59:34

--

It seems that cleaning the temp files helped get rid of some of the junk. The pop-ups ceased after I deleted them.

The biggest problem I seemed to have with this fix was the rebooting. Vista blocked the malware remover program without my permission, and despite my attempts, I couldn't remove it from the list. Luckily, Combofix had no trouble getting through.

#4 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:08:39 PM

Posted 20 April 2008 - 09:14 AM

Hello L. Soule,

Well done :thumbsup:
But we're not out of the woods yet.

Let's clean up some more :

Open Notepad - don't use any other texteditor than Notepad or the script will fail !
Copy/paste the bold, blue text below into an empty notepad window:File::
C:\Windows\System32\drivers\mrxsmbb.sys
C:\Windows\System32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll-uninst.exe
C:\Windows\System32\6164.bat
C:\Windows\System32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll
C:\ProgramData\SIXTH TWO TWO.rq6qp
Folder::
C:\Temp\tn3
C:\Windows\ZGF5bmU
C:\Windows\System32\vFi
C:\Windows\System32\pinz1
C:\Windows\System32\IDE2
C:\Windows\System32\ExTmp
C:\Windows\System32\bharebio05
C:\Temp\wdlw14
C:\Users\All Users\Admin Inter 1 Mags
C:\ProgramData\Admin Inter 1 Mags
C:\Users\All Users\File bold bib
C:\ProgramData\File bold bib
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{90ee6848-d086-25fd-4b25-73d4ae6a5c38}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4cdccf34]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fast mix]

Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again. Upon reboot, (in case it asks to reboot), post the contents of the Combofix log in your next reply, as well as a fresh HijackThislog.

Are you still having problems ?

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#5 L. Soule

L. Soule
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Taunton, MA, USA
  • Local time:02:39 PM

Posted 20 April 2008 - 01:06 PM

ComboFix 08-04-18.3 - dayne 2008-04-20 13:35:18.3 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.1261 [GMT -4:00]
Running from: C:\Users\dayne\Desktop\ComboFix.exe
Command switches used :: C:\Users\dayne\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


FILE ::
C:\ProgramData\SIXTH TWO TWO.rq6qp
C:\Windows\System32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll
C:\Windows\System32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll-uninst.exe
C:\Windows\System32\6164.bat
C:\Windows\System32\drivers\mrxsmbb.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\tn3
C:\Windows\system32\drivers\core.cache.dsk
C:\Windows\System32\drivers\mrxsmbb.sys
.
---- Previous Run -------
.
C:\ProgramData\Admin Inter 1 Mags
C:\ProgramData\Admin Inter 1 Mags\BLUE INFO.exe
C:\ProgramData\Admin Inter 1 Mags\Roam file.exe
C:\ProgramData\File bold bib
C:\ProgramData\File bold bib\Loadinside.exe
C:\ProgramData\File bold bib\ruquuqpz.exe
C:\ProgramData\File bold bib\wiflcrdw.exe
C:\ProgramData\SIXTH TWO TWO.rq6qp
C:\temp\tn3
C:\Temp\wdlw14
C:\Temp\wdlw14\maxN1bo.log
C:\Users\All Users\Admin Inter 1 Mags\BLUE INFO.exe
C:\Users\All Users\Admin Inter 1 Mags\Roam file.exe
C:\Users\All Users\File bold bib\Loadinside.exe
C:\Users\All Users\File bold bib\ruquuqpz.exe
C:\Users\All Users\File bold bib\wiflcrdw.exe
C:\Windows\System32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll-uninst.exe
C:\Windows\System32\{2d0e89bb-96ad-5de6-e89e-be0bf59f1cb1}.dll
C:\Windows\System32\6164.bat
C:\Windows\System32\bharebio05
C:\Windows\System32\ExTmp
C:\Windows\System32\IDE2
C:\Windows\System32\IDE2\mdllcom2.exe
C:\Windows\System32\pinz1
C:\Windows\System32\vFi
C:\Windows\System32\vFi\SCEE509.exe
C:\Windows\ZGF5bmU

.
((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.

2008-04-19 11:41 . 2008-04-19 12:43 <DIR> d-------- C:\Users\dayne\AppData\Roaming\OpenOffice.org2
2008-04-19 11:23 . 2008-04-19 11:23 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Malwarebytes
2008-04-19 11:23 . 2008-04-19 11:23 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-04-19 11:23 . 2008-04-19 11:23 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-04-19 11:23 . 2008-04-19 11:23 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-19 11:03 . 2008-04-19 11:03 100 --a------ C:\Windows\System32\ikhcore.cfg
2008-04-16 16:04 . 2008-04-16 16:04 <DIR> d-------- C:\Deckard
2008-04-16 11:56 . 2008-04-16 11:56 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-04-16 11:56 . 2008-04-16 11:56 <DIR> d-------- C:\Users\All Users\Kaspersky Lab
2008-04-16 11:56 . 2008-04-16 11:56 <DIR> d-------- C:\ProgramData\Kaspersky Lab
2008-04-15 13:07 . 2008-04-15 13:07 <DIR> d-------- C:\Users\dayne\AppData\Roaming\PC Tools
2008-04-15 13:07 . 2008-04-15 14:07 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-04-15 13:07 . 2007-12-10 14:53 81,288 --a------ C:\Windows\System32\drivers\iksyssec.sys
2008-04-15 13:07 . 2007-12-10 14:53 66,952 --a------ C:\Windows\System32\drivers\iksysflt.sys
2008-04-15 13:07 . 2008-02-01 12:55 42,376 --a------ C:\Windows\System32\drivers\ikfilesec.sys
2008-04-15 13:07 . 2007-12-10 14:53 29,576 --a------ C:\Windows\System32\drivers\kcom.sys
2008-04-15 09:25 . 2008-04-20 13:45 5,246 --a------ C:\Windows\System32\Config.MPF
2008-04-15 09:18 . 2006-03-03 11:07 143,360 --a------ C:\Windows\System32\dunzip32.dll
2008-04-15 09:14 . 2008-02-06 09:51 171,400 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-04-15 09:14 . 2007-03-02 14:17 120,360 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-04-15 09:14 . 2007-06-25 14:54 71,496 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-04-15 09:14 . 2007-06-25 10:57 37,480 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-04-15 09:14 . 2007-06-25 10:57 34,184 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-04-15 09:14 . 2007-06-25 10:57 32,008 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-04-15 09:13 . 2008-04-15 09:13 <DIR> d-------- C:\Program Files\McAfee.com
2008-04-15 09:13 . 2008-04-15 09:23 <DIR> d-------- C:\Program Files\McAfee
2008-04-15 09:13 . 2008-04-15 09:18 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-04-15 03:51 . 2008-04-20 13:32 <DIR> d-------- C:\Users\All Users\Google Updater
2008-04-15 03:51 . 2008-04-20 13:32 <DIR> d-------- C:\ProgramData\Google Updater
2008-04-14 21:12 . 2008-04-14 21:12 <DIR> d-------- C:\Users\Mom\AppData\Roaming\Paltalk
2008-04-14 15:57 . 2008-04-15 10:50 <DIR> d--hs---- C:\Users\dayne\'
2008-04-14 15:53 . 2008-04-20 13:35 <DIR> d-------- C:\Temp
2008-04-13 14:54 . 2008-04-13 14:54 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Camfrog
2008-04-13 14:54 . 2008-04-13 14:54 <DIR> d-------- C:\Program Files\Camfrog
2008-04-13 14:38 . 2008-04-13 14:38 <DIR> d-------- C:\Windows\PaltalkScene
2008-04-13 14:38 . 2008-04-13 14:40 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Paltalk
2008-04-13 14:38 . 2008-04-13 14:38 <DIR> d-------- C:\Program Files\Paltalk Messenger
2008-04-13 00:21 . 2008-04-13 00:21 <DIR> d-------- C:\Program Files\AvPropPlugin
2008-04-12 23:54 . 2008-04-12 23:54 <DIR> d-------- C:\Users\All Users\Logitech
2008-04-12 23:54 . 2008-04-12 23:59 <DIR> d-------- C:\Users\All Users\Logishrd
2008-04-12 23:54 . 2008-04-12 23:54 <DIR> d-------- C:\ProgramData\Logitech
2008-04-12 23:54 . 2008-04-12 23:59 <DIR> d-------- C:\ProgramData\Logishrd
2008-04-12 23:54 . 2008-04-12 23:54 <DIR> d-------- C:\Program Files\Logitech
2008-04-12 23:52 . 2008-04-12 23:55 <DIR> d-------- C:\Program Files\Common Files\logishrd
2008-04-12 20:48 . 2008-04-12 20:48 <DIR> d-------- C:\Windows\System32\Adobe
2008-04-12 15:12 . 2008-04-12 15:12 <DIR> d-------- C:\Users\dayne\AppData\Roaming\WildTangent
2008-04-11 23:43 . 2008-04-14 15:38 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Yahoo!
2008-04-08 11:40 . 2008-04-08 11:40 <DIR> d-------- C:\Users\dayne\AppData\Roaming\Talkback
2008-04-08 00:32 . 2008-04-08 00:32 <DIR> d-------- C:\Users\Leon\AppData\Roaming\OpenOffice.org2
2008-04-08 00:27 . 2008-04-08 01:04 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-04-07 17:09 . 2006-05-31 15:25 25,088 --a------ C:\Windows\System32\msxml3a.dll
2008-04-06 14:09 . 2008-04-06 14:09 <DIR> d-------- C:\Users\Leon\AppData\Roaming\Template
2008-04-06 14:09 . 2008-04-06 14:20 540 --a------ C:\Users\Leon\AppData\Roaming\wklnhst.dat
2008-04-05 22:17 . 2008-04-05 22:17 <DIR> d-------- C:\Users\Leon\AppData\Roaming\U3
2008-04-05 02:15 . 2008-04-14 15:38 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-04 20:12 . 2008-04-05 02:16 <DIR> d-------- C:\Users\Leon\AppData\Roaming\Apple Computer
2008-04-04 20:11 . 2008-04-04 20:12 54,156 --ah----- C:\Windows\QTFont.qfn
2008-04-04 20:11 . 2008-04-04 20:12 1,409 --a------ C:\Windows\QTFont.for
2008-04-04 20:09 . 2008-04-05 02:19 <DIR> d-------- C:\Users\All Users\Apple Computer
2008-04-04 20:09 . 2008-04-05 02:19 <DIR> d-------- C:\ProgramData\Apple Computer
2008-04-04 20:09 . 2008-04-04 20:09 <DIR> d-------- C:\Program Files\QuickTime
2008-04-03 17:40 . 2008-04-03 17:40 <DIR> d-------- C:\Users\Leon\AppData\Roaming\COWON
2008-04-03 17:35 . 2008-04-03 18:39 <DIR> d-------- C:\Users\Leon\Shared
2008-04-03 17:35 . 2008-04-03 19:32 <DIR> d-------- C:\Users\Leon\Incomplete
2008-04-03 17:35 . 2008-04-03 17:40 <DIR> d-------- C:\Users\Leon\AppData\Roaming\LimeWire
2008-04-03 14:10 . 2008-04-03 14:10 <DIR> d-------- C:\Users\Leon\AppData\Roaming\Talkback
2008-04-03 13:57 . 2008-04-03 13:57 <DIR> d-------- C:\Users\Leon\AppData\Roaming\acccore
2008-04-03 13:53 . 2008-04-08 01:11 <DIR> dr------- C:\Users\Leon\Videos
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> dr------- C:\Users\Leon\Searches
2008-04-03 13:53 . 2008-04-03 22:51 <DIR> dr------- C:\Users\Leon\Saved Games
2008-04-03 13:53 . 2008-04-08 01:13 <DIR> dr------- C:\Users\Leon\Pictures
2008-04-03 13:53 . 2008-04-08 01:12 <DIR> dr------- C:\Users\Leon\Music
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> dr------- C:\Users\Leon\Links
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> dr------- C:\Users\Leon\Downloads
2008-04-03 13:53 . 2008-04-08 01:10 <DIR> dr------- C:\Users\Leon\Documents
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> dr------- C:\Users\Leon\Contacts
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> d-------- C:\Users\Leon\AppData\Roaming\Gtek
2008-04-03 13:53 . 2008-04-03 13:53 <DIR> d--h----- C:\Users\Leon\AppData
2008-04-03 13:53 . 2008-04-08 01:13 <DIR> d-------- C:\Users\Leon
2008-04-03 13:53 . 2008-04-03 19:33 524,288 --ahs---- C:\Users\Leon\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms
2008-04-03 13:53 . 2008-04-03 19:33 524,288 --ahs---- C:\Users\Leon\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
2008-04-03 13:53 . 2008-04-19 12:55 262,144 --ah----- C:\Users\Leon\ntuser.dat.LOG1
2008-04-03 13:53 . 2008-04-03 19:33 65,536 --ahs---- C:\Users\Leon\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
2008-04-03 13:53 . 2008-04-03 13:53 0 --ah----- C:\Users\Leon\ntuser.dat.LOG2
2008-04-02 18:42 . 2008-04-02 20:59 524,288 --ahs---- C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{11177e9e-0106-11dd-92de-001644735690}.TMContainer00000000000000000002.regtrans-ms
2008-04-02 18:42 . 2008-04-02 20:59 524,288 --ahs---- C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{11177e9e-0106-11dd-92de-001644735690}.TMContainer00000000000000000001.regtrans-ms
2008-04-02 18:42 . 2008-04-02 20:59 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{11177e9a-0106-11dd-92de-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms
2008-04-02 18:42 . 2008-04-02 20:59 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{11177e9a-0106-11dd-92de-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
2008-04-02 18:42 . 2008-04-02 20:59 65,536 --ahs---- C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{11177e9e-0106-11dd-92de-001644735690}.TM.blf
2008-04-02 18:42 . 2008-04-02 20:59 65,536 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{11177e9a-0106-11dd-92de-806e6f6e6963}.TM.blf
2008-04-02 17:59 . 2008-04-02 17:59 2,560 --a------ C:\Windows\_MSRSTRT.EXE
2008-03-29 12:00 . 2008-04-15 09:22 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-29 11:59 . 2008-04-13 18:02 <DIR> d-------- C:\Users\All Users\Symantec
2008-03-29 11:59 . 2008-04-13 18:02 <DIR> d-------- C:\ProgramData\Symantec
2008-03-29 11:57 . 2008-04-19 11:25 <DIR> d-a------ C:\Users\All Users\TEMP
2008-03-29 11:57 . 2008-04-19 11:25 <DIR> d-a------ C:\ProgramData\TEMP
2008-03-29 03:17 . 2008-03-29 03:17 <DIR> d-------- C:\Users\All Users\WLInstaller
2008-03-29 03:17 . 2008-03-29 03:17 <DIR> d-------- C:\ProgramData\WLInstaller
2008-03-29 03:17 . 2008-03-29 03:17 <DIR> d-------- C:\Program Files\Windows Live
2008-03-29 03:17 . 2008-03-29 03:19 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\Windows\System32\QuickTime.qts
2008-03-28 03:24 . 2008-03-28 03:24 <DIR> d-------- C:\Users\All Users\Azureus
2008-03-28 03:24 . 2008-03-28 03:24 <DIR> d-------- C:\ProgramData\Azureus
2008-03-24 23:49 . 2008-03-24 23:49 <DIR> d-------- C:\Program Files\Bonjour
2008-03-24 23:47 . 2008-03-24 23:47 <DIR> d-------- C:\Users\All Users\Apple
2008-03-24 23:47 . 2008-03-24 23:47 <DIR> d-------- C:\ProgramData\Apple
2008-03-23 21:11 . 2008-03-23 21:11 <DIR> d-------- C:\Program Files\EO Video
2008-03-23 21:11 . 2008-03-23 21:11 724,992 --a------ C:\Windows\iun6002.exe
2008-03-23 05:50 . 2004-03-09 00:00 662,288 --a------ C:\Windows\System32\mscomct2.ocx
2008-03-23 05:50 . 2004-03-09 00:00 212,240 --a------ C:\Windows\System32\richtx32.ocx
2008-03-23 05:50 . 2000-05-19 17:56 81,920 --a------ C:\Windows\System32\mbmouse.ocx
2008-03-23 05:50 . 2000-11-05 15:27 36,864 --a------ C:\Windows\System32\trayicon.ocx
2008-03-20 20:56 . 2008-04-02 18:15 <DIR> d-------- C:\Program Files\Common Files\Real

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 17:29 --------- d-----w C:\Users\dayne\AppData\Roaming\U3
2008-04-15 13:23 --------- d-----w C:\ProgramData\McAfee
2008-04-15 07:51 --------- d-----w C:\Program Files\Google
2008-04-14 20:06 --------- d-----w C:\Users\dayne\AppData\Roaming\LimeWire
2008-04-14 20:05 --------- d-----w C:\Program Files\LimeWire
2008-04-14 19:38 --------- d-----w C:\ProgramData\Yahoo!
2008-04-14 19:38 --------- d-----w C:\ProgramData\Viewpoint
2008-04-14 19:37 --------- d-----w C:\Users\dayne\AppData\Roaming\MP3Rocket
2008-04-12 19:12 --------- d-----w C:\ProgramData\WildTangent
2008-04-09 11:06 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-08 04:27 --------- d-----w C:\Program Files\Java
2008-04-02 22:18 --------- d-----w C:\Program Files\Common Files\Logitech
2008-04-01 14:36 --------- d-----w C:\Users\Mom\AppData\Roaming\OpenOffice.org2
2008-03-25 07:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-25 07:03 --------- d-----w C:\ProgramData\Napster
2008-03-17 22:21 --------- d-----w C:\Users\Mom\AppData\Roaming\acccore
2008-03-15 14:30 --------- d-----w C:\Users\Guest\AppData\Roaming\OpenOffice.org2
2008-03-12 00:53 --------- d-----w C:\Program Files\AIM
2008-03-12 00:31 --------- d-----w C:\Program Files\AOD
2008-03-11 16:17 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-09 16:50 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-05 14:44 --------- d-----w C:\Users\Mom\AppData\Roaming\Talkback
2008-03-05 14:41 --------- d-----w C:\Users\Mom\AppData\Roaming\Gtek
2008-03-05 14:41 --------- d-----w C:\Users\Mom\AppData\Roaming\ATI
2008-03-03 18:38 --------- d-----w C:\Users\Guest\AppData\Roaming\Talkback
2008-03-03 08:16 --------- d-----w C:\ProgramData\ArcSoft
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-21 02:03 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-02-17 16:32 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-17 16:30 613,888 ----a-w C:\Windows\System32\wpd_ci.dll
2008-02-17 16:30 224,824 ----a-w C:\Windows\System32\clfs.sys
2008-02-17 16:30 221,696 ----a-w C:\Windows\System32\umpnpmgr.dll
2008-02-17 16:30 19,456 ----a-w C:\Windows\System32\cfgmgr32.dll
2008-02-17 16:30 101,888 ----a-w C:\Windows\System32\drvinst.exe
2008-02-17 16:29 905,400 ----a-w C:\Windows\System32\winresume.exe
2008-02-17 16:29 595,456 ----a-w C:\Windows\System32\schedsvc.dll
2008-02-17 16:29 558,080 ----a-w C:\Windows\System32\oleaut32.dll
2008-02-17 16:29 39,424 ----a-w C:\Windows\System32\lodctr.exe
2008-02-17 16:29 35,328 ----a-w C:\Windows\System32\dispci.dll
2008-02-17 16:29 32,256 ----a-w C:\Windows\System32\unlodctr.exe
2008-02-17 16:29 260,096 ----a-w C:\Windows\System32\dpx.dll
2008-02-17 16:29 23,552 ----a-w C:\Windows\System32\nshhttp.dll
2008-02-17 16:29 17,408 ----a-w C:\Windows\System32\prflbmsg.dll
2008-02-17 16:29 12,800 ----a-w C:\Windows\System32\batt.dll
2008-02-17 16:29 115,200 ----a-w C:\Windows\System32\loadperf.dll
2008-02-17 16:29 1,585,664 ----a-w C:\Windows\System32\setupapi.dll
2008-02-17 16:27 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-17 16:27 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-17 16:27 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
2007-12-05 17:15 0 ----a-w C:\Users\dayne\AppData\Roaming\wklnhst.dat
2006-11-02 12:48 174 --sha-w C:\Program Files\desktop.ini
2007-12-25 22:16 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-12-25 22:16 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-12-25 22:16 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((( snapshot@2008-04-19_13.06.43.92 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-19 17:00:39 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-20 17:40:06 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-04-19 16:58:58 1,057,320 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2008-04-20 17:38:24 1,057,320 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2008-04-19 17:00:40 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-04-20 17:40:07 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-04-19 17:00:40 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-04-20 17:40:07 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-04-19 17:04:09 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-04-20 17:44:41 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-04-19 17:04:10 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-20 17:44:41 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-04-19 15:03:43 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-20 17:25:34 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-04-19 15:03:43 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-20 17:25:34 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-19 15:03:43 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-04-20 17:25:34 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-19 16:52:02 104,024 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-04-20 17:30:13 104,024 ----a-w C:\Windows\System32\perfc009.dat
- 2008-04-19 16:52:02 618,648 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-04-20 17:30:13 618,648 ----a-w C:\Windows\System32\perfh009.dat
- 2008-04-19 16:48:24 5,688 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2556700239-1881780036-892603058-1000_UserData.bin
+ 2008-04-20 17:27:22 6,134 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2556700239-1881780036-892603058-1000_UserData.bin
- 2008-04-19 16:48:24 69,792 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-20 17:27:22 70,108 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-04-19 16:48:23 65,296 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-20 17:17:43 65,930 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 19:16 454784]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 04:04 1232896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-05 14:32 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-09 22:26 4702208 C:\Windows\RtHDVCpl.exe]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 13:39 411192]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [2006-12-07 19:49 55416]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 00:01 448080]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 19:32 538744]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-08-15 18:31 102400]
"NDSTray.exe"="NDSTray.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DelayShred"="C:\Program Files\McAfee\MSHR\ShrCL.exe" [2007-01-17 18:02 95784]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3B2AE162-5B9E-4266-8C2E-6799D53935AE}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{15337CF1-CCDD-4FF3-AD97-082E86621E93}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4AD4B5CC-4642-4046-97F3-53262E99A638}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{53EAA5F8-9CA0-4B7C-A093-665A1DBE2031}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{8062FEC8-BF1E-46F4-B4B9-0E10E0793FA0}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{9AEFB83C-FC67-45FF-BFBC-B074903CE7E7}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{325A9B89-691D-4449-ACF3-27E97155A173}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{BBA9C5D3-275F-43D2-B80A-A3615E7A6D25}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"{452B22EC-D64C-4E89-80EC-2CCFF12C0215}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{9856E870-5CCB-4952-9EA8-F16906F37967}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{73740713-B1B5-42C9-9991-C7DEE78112BD}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{95DF761D-C480-440B-B9ED-D0B687EAA98D}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{7A67B89F-BB78-4556-86E2-1EAA42529E6C}C:\\program files\\aim6\\aim6.exe"= UDP:C:\program files\aim6\aim6.exe:AIM
"UDP Query User{4D8DFEBF-D20C-413A-A877-A1D103ADC515}C:\\program files\\aim6\\aim6.exe"= TCP:C:\program files\aim6\aim6.exe:AIM
"TCP Query User{9DAFAFA2-0CDC-42DA-A0FB-DA95BC24571A}C:\\program files\\aim\\aim.exe"= UDP:C:\program files\aim\aim.exe:AOL Instant Messenger
"UDP Query User{DB1ADE73-6AB5-4896-B9A7-08F96BBEE140}C:\\program files\\aim\\aim.exe"= TCP:C:\program files\aim\aim.exe:AOL Instant Messenger
"TCP Query User{DEB8AE8F-FEE7-4293-B3FD-93741043C67A}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{E6DFDAAF-D8EF-4720-83CC-84410550C9B9}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"{6F8F2FD5-A3C5-42A0-A3AA-BE2502FAE24A}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{10AC395B-62C5-481C-A2AC-FBD67BA206CC}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{1BD9F629-41E4-49E9-95AE-71CCE0279E16}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{27B0DE0B-C6DD-4055-A54E-3559084A00D4}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"TCP Query User{78C094CE-9CFE-4D18-8F98-64F0AEDF8AA6}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{085A63E3-BD38-490C-B1B0-4C60994BEEDF}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"TCP Query User{3F30B3BA-0CF4-4618-A389-AF52F082D883}C:\\program files\\bitdownload\\bitdownload.exe"= UDP:C:\program files\bitdownload\bitdownload.exe:BitDownload
"UDP Query User{12EFE342-4F2B-44ED-9ACD-381791DA232D}C:\\program files\\bitdownload\\bitdownload.exe"= TCP:C:\program files\bitdownload\bitdownload.exe:BitDownload
"TCP Query User{3154CC9A-71E9-4CD6-986B-C994E2EF2BA0}C:\\program files\\paltalk messenger\\paltalk.exe"= UDP:C:\program files\paltalk messenger\paltalk.exe:PaltalkScene
"UDP Query User{A7BE98FF-65EC-46A1-8DC3-71DC60850BD0}C:\\program files\\paltalk messenger\\paltalk.exe"= TCP:C:\program files\paltalk messenger\paltalk.exe:PaltalkScene
"{CD757239-E883-46C1-8475-7BC9E2E32736}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger

R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 14:23]
R0 tos_sps32;TOSHIBA tos_sps32 Service;C:\Windows\system32\DRIVERS\tos_sps32.sys [2007-08-01 17:37]
R2 pinger;pinger;C:\Toshiba\IVP\ISM\pinger.exe [2007-01-25 20:47]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-28 02:36]
R3 FwLnk;FwLnk Driver;C:\Windows\system32\DRIVERS\FwLnk.sys [2006-11-20 02:11]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8187B.sys [2007-06-01 16:07]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 14:50]
S3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2006-11-02 03:30]
S3 tosrfec;Bluetooth ACPI;C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 19:32]
S3 winbondcir;Winbond IR Transceiver;C:\Windows\system32\DRIVERS\winbondcir.sys [2007-03-28 10:51]
S4 KR10I;KR10I;C:\Windows\system32\drivers\kr10i.sys [2006-11-09 02:32]
S4 KR10N;KR10N;C:\Windows\system32\drivers\kr10n.sys [2006-11-09 02:31]
S4 KR3NPXP;KR3NPXP;C:\Windows\system32\drivers\kr3npxp.sys [2006-09-27 08:06]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-04-15 13:22:50 C:\Windows\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-04-15 13:22:50 C:\Windows\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-04-20 17:45:17 C:\Windows\Tasks\User_Feed_Synchronization-{66F1B511-026D-4EC3-B6B7-E13E4509186D}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 13:44:56
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\Ati2evxx.exe
C:\Windows\System32\agrsmsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\COMMON~1\McAfee\RedirSvc\RedirSvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\System32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Windows\System32\wbem\WMIADAP.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
.
**************************************************************************
.
Completion time: 2008-04-20 13:47:46 - machine was rebooted [dayne]
ComboFix-quarantined-files.txt 2008-04-20 17:47:38
ComboFix2.txt 2008-04-19 17:07:30

Pre-Run: 80,104,812,544 bytes free
Post-Run: 80,068,730,880 bytes free

422 --- E O F --- 2008-04-13 17:59:34

--

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:54:03 PM, on 4/20/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Windows\Explorer.exe
C:\Users\dayne\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kaspersky.com/virusscanner
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P2 /q C:\Users\dayne\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WA8LNGUE\TCODE_~2.SH! (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P2 /q C:\Users\dayne\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WA8LNGUE\TCODE_~2.SH! (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 8695 bytes

--

The above scan for combofix might not be as complete as it should be. Apparently, windows automatically began installing updates while it was running, and my computer crashed. I rebooted cf after the update was finished, and that was the result.

I can't see anything out of the ordinary, save the missing files in HJT. (: Of course, I'm not expert... I do know, however, that my computer appears to be acting normally again. What's your take?

#6 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:08:39 PM

Posted 20 April 2008 - 04:15 PM

Hello L. Soule,

Your log looks fine. :thumbsup:

Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following, if still present :R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Your JavaVM is also out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u6.
  • Scroll down to where it says The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the Download button to the right.
  • Check the box that says: Accept License Agreement
  • The page will refresh.
  • Click on the link to download Windows Offline Installation (jre-6u6-windows-i586-p.exe) and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
No problems anymore ?

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#7 L. Soule

L. Soule
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Taunton, MA, USA
  • Local time:02:39 PM

Posted 21 April 2008 - 07:36 AM

Done, and done.

All clear! I'm forever in your debt. (: Thank you. I've installed security software on this computer, and advised my brother on internet safety so as to prevent this from happening again.

#8 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:08:39 PM

Posted 21 April 2008 - 01:09 PM

Glad we could help, L. Soule :thumbsup:

You can remove all used tools and folders created in the process.
To remove ComboFix :
Go to Start > Run, and copy and paste next command in the field:ComboFix /u
Make sure there's a space between Combofix and /u
Then press Enter.
This will uninstall Combofix, delete its related folders and files, restore your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Please read this Prevention page with lots of info and tips how to prevent this in the future.
And if you want to improve speed/system performance after malware removal, take a look here.
Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks.
To find out what programs need to be updated, please run the Secunia Software Inspector Scan.

Please also read Tony Klein's excellent article: How I got Infected in the First Place
and/or Grinlers tutorial on how malware is hidden and installed

Since this issue appears resolved ... this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users