Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Search Redirect Malware


  • This topic is locked This topic is locked
15 replies to this topic

#1 MaxwellHouse

MaxwellHouse

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 14 December 2008 - 05:47 PM

Hi there,

When clicking on search results in Google, the expected (and displayed) website does not come up. I am instead redirected to another search website 'andfindthis.com' etc.

Please help.

Attached are my Hijackthis.log and RSIT info and log.

Thanks!

Attached Files



BC AdBot (Login to Remove)

 


#2 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:11:26 AM

Posted 15 December 2008 - 03:06 PM

Hello! :thumbsup:
My name is Sam and I will be helping you.

In order to see what's going on with your computer I may ask for you to post various logs from the tools that we will use to resolve your issue. Please also share with me any information about how your computer is reacting and behaving each step of the way as we work through this process.


Please download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back here in your next reply.

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#3 MaxwellHouse

MaxwellHouse
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 16 December 2008 - 12:02 PM

Hi Sam,

Thanks for your reply. I've done as instructed - the only problem now is I can't access the internet anymore! I'm currently responding from my work PC. Hopefully this is expected or easily fixed. :thumbsup:

Here's the report.txt from SDFix:

SDFix: Version 1.240
Run by Mike on Mon 12/15/2008 at 10:54 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :

Name :
Network Location Awareness (NLA) (Nla)

Path :
C:\Program Files\tinyproxy\tinyproxy.exe

Network Location Awareness (NLA) (Nla) - Deleted



Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\Program Files\TinyProxy\TinyProxy.exe - Deleted



Folder C:\Program Files\TinyProxy - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-15 23:12:03
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Valve\\Steam\\Steam.exe"="C:\\Program Files\\Valve\\Steam\\Steam.exe:*:Enabled:Steam"
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"="C:\\Program Files\\BitTornado\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\Program Files\\BitTorrent\\btdownloadgui.exe"="C:\\Program Files\\BitTorrent\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Sierra\\FEAR\\fpupdate.exe"="C:\\Program Files\\Sierra\\FEAR\\fpupdate.exe:*:Enabled:fpupdate"
"C:\\Program Files\\Microsoft Games\\Rise Of Legends Demo\\legends.exe"="C:\\Program Files\\Microsoft Games\\Rise Of Legends Demo\\legends.exe:*:Disabled:Rise of Legends"
"C:\\Program Files\\Palm\\HOTSYNC.EXE"="C:\\Program Files\\Palm\\HOTSYNC.EXE:*:Enabled:HotSyncr Manager Application"
"C:\\Program Files\\World of Warcraft\\WoW-1.11.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.11.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.11.1.5462-to-1.11.2.5464-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
"C:\\Program Files\\Abacast\\Abaclient.exe"="C:\\Program Files\\Abacast\\Abaclient.exe:*:Enabled:Abaclient"
"C:\\Program Files\\ABC\\abc.exe"="C:\\Program Files\\ABC\\abc.exe:*:Enabled:abc"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\jetmike\\half-life\\hl.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\jetmike\\half-life\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\jetmike\\rag doll kung fu\\Rag_Doll_Kung_Fu_Steam.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\jetmike\\rag doll kung fu\\Rag_Doll_Kung_Fu_Steam.exe:*:Enabled:Rag_Doll_Kung_Fu_Steam"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\Soulseek-Test\\slsk.exe"="C:\\Program Files\\Soulseek-Test\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\Ubisoft\\Tom Clancy's Splinter Cell Chaos Theory\\System\\splintercell3.exe"="C:\\Program Files\\Ubisoft\\Tom Clancy's Splinter Cell Chaos Theory\\System\\splintercell3.exe:*:Enabled:splintercell3"
"C:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"="C:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe:*:Enabled:GPGNet - Supreme Commander - Forged Alliance"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\jetmike\\counter-strike source\\hl2.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\jetmike\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"="C:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe:*:Enabled:Soulstorm"
"C:\\Program Files\\Ubi Soft\\Splinter Cell\\system\\splinterCell.exe"="C:\\Program Files\\Ubi Soft\\Splinter Cell\\system\\splinterCell.exe:*:Enabled:splinterCell"
"C:\\Program Files\\Electronic Arts\\EADM\\Core.exe"="C:\\Program Files\\Electronic Arts\\EADM\\Core.exe:*:Enabled:EA Download Manager"
"C:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"="C:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe:*:Enabled:Sins of a Solar Empire"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"="C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe:*:Enabled:Crysis_32"
"C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"="C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe:*:Enabled:Far Cry 2"
"C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"="C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe:*:Enabled:Far Cry 2 Updater"
"C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"="C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe:*:Enabled:Editor"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\tinyproxy\\tinyproxy.exe"="C:\\Program Files\\tinyproxy\\tinyproxy.exe:*:Enabled:tinyproxy"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Disabled:Internet Explorer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sat 13 Dec 2008 26,112 ...H. --- "C:\WINDOWS\bolivar30.exe"
Sun 18 Jun 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 29 Nov 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Sat 13 Dec 2008 18,650 ...HR --- "C:\Documents and Settings\Mike\Application Data\SecuROM\UserData\securom_v7_01.bak"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS024088F1-CF54-4DDE-80A6-DEB4200C42B7.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0349ED02-5F2D-4A16-B81D-D495152D5867.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS04BBF505-AC1C-41D0-9EB1-1F5E1BE185F3.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS08E06B33-589A-4164-9A08-B8E5BBF12D06.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0912F00D-91ED-4DA7-87DF-BBC2EEC7597B.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0C68DD0B-2DFF-4DDF-8E31-7FC28CD94B39.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0C05567A-0D1A-458F-9464-29B71D50D4EC.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0E7692E5-CD4E-4617-B146-8446E590D05A.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1229CD0C-70FB-4524-AF2C-5CEC63D5DE46.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS135868D3-00CD-478E-B8C2-ED8D76EA1004.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS149BDEFF-4E44-4DDF-A54F-BE90759333E7.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS159B67EF-D9C0-4603-9493-129FDE15304A.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS167F9B96-6ED7-409E-B6E0-A4B3C818CFD8.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS178A8DAF-AC74-4B26-8ACD-7547B91BDB87.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1DF43547-2EFD-46F6-996A-9AA70D8CDCD8.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1D202B90-ECF2-462E-893C-3FB6224C9E03.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS20CF10D1-2ED6-4F49-B505-8E0E3ABC5FAB.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS219812F6-71FA-4195-9595-381116B92DAA.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS28B5FD3D-F606-431A-A61A-384D6560469F.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2ECEAFE4-5BDB-4831-86C4-E841AF53F1F8.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS31B8B0E8-8B16-48E9-8FBA-EC92AC2D70EB.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS321F7E39-D02D-45C9-8EEC-993E15A81148.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS353D160E-10E9-4B48-8156-73068EE23F4E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS365A0F2B-2D87-4562-9FF7-50672FC866CA.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3D526F57-A7B6-4C64-8C0E-028592828DB8.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS42D603F2-D742-4330-A03B-D1E2CDC87A49.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS43B114F4-2094-46EC-99DB-C1066ECE17F0.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4953CEED-5AC4-4138-8F01-5304168D3B96.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4D856B80-C13B-4D5A-9E7D-DA13E43AB0B9.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4F214B33-4F69-4F72-A70A-5BEDEF8D2647.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS544D2F30-BBB9-49F5-B1F3-F27CA55F1C13.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS54333E49-A611-46D0-83B1-B386464FD2B7.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5501E6D8-4019-4D24-AA2C-24A53FF8570C.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS57E49B70-D6B6-4DE6-99B1-3EE74E8CD56E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS58B648E3-080B-4E1E-8BC9-69C933D001CA.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS58F23CC9-D591-4E21-9045-8AC3793E3C2E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS580C5FA2-597E-4CA8-971F-9C87906CBA08.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS59B317FA-CAB2-44D4-8224-180809359BA9.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS604EDF26-4DE8-4546-A6C9-488E9FC1A78E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS659B0D59-091B-4DA7-9A8B-ED78FAC4DAD5.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS68122F9C-CB83-437D-8ECB-16490EF92636.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS69B4DE08-EEB2-482F-9BA6-296A87354438.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6A54A214-C3A2-412E-8440-132F01CF2130.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6C99A80B-0FF9-4429-9AF0-95044A29A0F1.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6DB3E897-81A9-40BE-9B13-6E59099FF041.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS77B87578-8853-41D0-B6D5-202644840DAE.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7A379E4E-0D1B-4106-9751-99CE12150199.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7B2506A2-6268-4D32-A5D5-8EDA42016461.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7C25CF92-4F6A-4547-AF6B-9E8147815484.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7D1A7DFB-1412-408E-9DBE-3F3DCF36B332.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS82E31E54-A03C-48DC-9087-C8CE522290C2.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8494375A-34E2-44FF-8D68-62A40EDFD1C0.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS898B0AB9-EA34-41EA-90BF-D5CDA44475DC.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8CF37BA4-F17D-4962-A9A7-4B5A6F23F41B.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8E148315-8554-4A6E-8E05-DB0D18F51E39.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8EE66A65-8F87-4D52-A757-755FB0117C8B.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8F40798C-D010-47A8-A6EB-C75DB5525155.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS95F9333A-7B68-4B56-A365-83EA2F777036.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS964CC73B-F749-42A2-A399-AD626568052B.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS99FFBFA1-F39F-4A31-B803-C7626CD43B15.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9B2EF150-8DFC-47E7-AAFF-5FCD9C7E974B.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9E4F5B8C-2695-4C80-9749-D9E40520E3A3.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9E7329F8-0D53-434D-8F9C-DB1DCDB7D16A.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA21A631B-8C60-498B-A5B4-B3589987F85E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA34B4D17-2B73-42FE-A69D-89643755808D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA50A9937-77B4-4B8A-AEF0-AEAB1D9F0214.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA7CF0C7F-763D-4A6D-8F61-BEDC7A61FA99.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA74D9901-A32F-4EFF-8275-DFEBBD7AC58B.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAD3A6D58-61E6-40DA-A2CE-AE7E8FA4D738.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAE6FFC2D-6105-41C3-A3D6-E36E860D81AE.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAF73B76A-DAA3-4B67-A637-CD80153C2D0C.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB75934DE-9405-47D0-8FA2-6D8136F44D87.tmp"
Mon 15 Dec 2008 65,536 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBFBE4C7C-24AC-48B0-A381-434834FCFBB4.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBFEB2325-4161-4B05-9CE3-090014B9C576.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC48EADE9-FCAA-4BCD-B82E-295EBE3B82A2.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC5E4FDA1-A8C4-4D5E-9766-9CB48703DB48.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCB2F13BF-EFE3-4935-8E6C-A28F47423E85.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCCBB431C-0211-4020-A9C7-BBF3323FEC57.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCEFC4AC6-A965-44FC-A1B0-DC18BA01389D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCEC7197E-6F40-4A4A-8945-25A03EA62902.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD3B82A53-2FDE-4CDB-80D7-74D09391E050.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD4A0C4E6-D397-473A-A633-9BC4757A6009.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDA5C876D-CF02-47DC-BE6B-22DAFD972DCE.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDA60F6F0-8059-490E-8C2B-2C01181206FF.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDD743E80-7ACC-4B31-901D-B612B0E9107F.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDD48C671-0CCE-4B1A-8441-77DE3511F273.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDE5434F2-3C25-46E9-9650-9D3FE7F4A6C3.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDE8A4972-BB89-4FAA-804C-BB83B318B327.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDFDC879C-5F1A-47AD-8514-1BFA095EB83B.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE5329442-5A82-4BD1-8DD3-A3233139BEA0.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE73C6FE9-F632-4EE1-B5FB-AB88B88C02E5.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE8C2AF90-9AFA-4631-AB49-8396F0E4935D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE85914F9-4901-42B9-9053-DA5EE0157618.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE978A078-2EAA-4459-831E-3A4C515E6EC9.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE9CFB0F2-36D2-4B3B-8E45-F72BCFF7FE9E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEE470CC0-C7CA-4AE5-AE42-FCC8E692EED8.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF3614A6F-3CC0-4124-842C-4D08C2E6F9DE.tmp"
Mon 15 Dec 2008 65,536 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF6544EBB-CFFA-4AA9-BDBD-19BACD0D9C21.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF6627704-DDA7-428E-89EE-BCF29556B91C.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF7A9153F-8A5A-4AEB-8921-A60AE408BEAB.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF8896816-C5E0-4A5A-A54C-D99D9EDF1D14.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFA50DB5E-EA64-44D0-A12E-B85ADF41E345.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFBF22C23-59AD-4E60-88BE-4C3BDAFDE027.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFF0FA40E-2519-46E4-A72F-E34091C4C8D6.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS050DC089-3F61-4501-96BD-4C611BE1CA21.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS061BBD01-52E8-4DB4-A3E1-DC1B4B265689.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0C5FEF9F-65ED-42BB-B0DD-A0C944ECD04B.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0CF9D076-9D7C-47A8-B916-CA82069FB6B0.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0C8CD5A3-090D-4DE5-9D40-2CCDD85F6E0F.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS11D4F139-0BC0-465A-A182-4739C3691C42.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS12D33145-2E94-4C49-A1CA-1282F9E0C37E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS12B135E0-0FC1-4604-8D4E-290932686C0D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS13341AB1-10C7-4D6B-B16D-084B3E167D11.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS13E9CC56-9BD2-4939-9F70-A6638BDCB279.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1493C0A4-4745-4B86-AFD0-7466BA20E304.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS17418AB4-91C8-4967-8D1F-495DFA74C9BA.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS18C08374-0E63-4362-A9D8-FECD0CB340CF.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A47FE5F-FAD9-4428-A958-B10B1531DA6D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A5CEAAF-DA83-413D-9DE5-D29693952FE3.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2BAF681F-88FB-4D46-8A8A-29F73155E1C8.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2DDA6E4E-2143-4564-9605-9CF6C40D6468.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2DDDBD97-8959-4B2E-A5E4-285DCA86DD27.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2E14BE57-A9DC-42F8-82FA-3EF20DEDA910.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2EA6D3E1-BF4C-445E-90A4-4E2B0203FAB9.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2F32E229-39FA-42F9-81D6-C6B213FD8EFF.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS37956347-7696-4E2C-93E0-ED81FBDBCB17.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS38033A69-8FD9-4949-9F40-EA99026651AC.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS39864D3B-ED2A-4FD4-9D89-EB559A909286.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3D0F6348-74BD-4155-B5F6-0DF56555EA15.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3D17D3B9-BD0F-4CDC-90CA-A561EB38FBE1.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3F9A1384-0559-45BE-B6C3-39E659936E52.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS42167F8F-D430-4509-A611-EB9FF63CAC05.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS42F2B93D-6B64-4E54-9557-631BD26693EE.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS43A7BA7B-8ED2-4CEB-94EC-FBF41228D236.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS43E87BEA-8989-41AE-9D2E-0E7A0ACB3B1D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS486B9A3B-751A-4785-BA9D-0C4B3A4F92E2.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS48A39745-A75F-4381-A052-17D4A5ACEFB9.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4DA4FE21-BF39-4AC9-92E2-236DAF79AFFD.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS52DE0686-6525-4BB7-AA7F-063DB02BD98B.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS530D5FB6-321C-4D2D-9C5B-F41917EBB47C.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5465EBB1-034A-4CAE-9ECE-DA6AB2C16DD5.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5599B019-B835-4CF6-AA8C-1FC3CD3E4C56.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS56559EF9-7360-42C0-9420-31A47FDFB6F6.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5719EA25-2886-431F-995A-2320E446144D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5AD7CAB1-2574-4964-95D6-E1DCE3A813D6.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5D556FEC-F3A2-4E7A-B06E-609D8D959B7A.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5D933829-8C2D-4FB7-85AF-7B070B1B5941.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6479E749-9FFF-4210-AE6E-0BA9250E1A6E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS65E34183-05D3-40FB-A55A-977B1D0191D3.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS664F0263-7D70-4F46-8276-59023D01E317.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6798D238-397D-4572-802B-328DC6C72991.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS68F5A9F8-1698-43C0-9C30-368B07651ABF.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6977E95A-DE3E-4B22-8174-0B932D8C0F71.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS695DB86D-F21C-4FDF-9A3C-F138D69D8C1D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6BD63AA1-7B8E-46E5-937A-4720AFEC0D6D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6F71D055-18FC-42FA-96CA-DFB95ADF3EE6.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7171134A-CABE-42EC-99AA-0C6AEF8CBD1C.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS724FF302-D447-4D70-8541-B34FA2315B0A.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS74DDCB04-F798-4F1C-AD2F-69210204275A.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS75682EE4-111D-4F1E-8212-1ED07E273975.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7547D7B0-A3D0-4CE8-9474-9F023B9595B5.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS765832C3-E642-418C-B61B-281211083CB4.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS77A6068F-C2C2-483C-A40C-D3105AB31E58.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS77DB9FBF-6F5A-4A7C-A295-D474C5675FF7.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS774A8F7E-0B5A-4208-AB28-53F1D3812B7C.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7924482B-A826-4455-AAE9-5EFDE7F8B6F9.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7CD367A0-D465-4C95-AA0C-5646BFAF25D7.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7D346E31-5EDF-44B0-9DE9-CCE6FA663638.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7D0E4CA3-DD3E-42B3-8587-95C8598D60A7.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7DF26303-9188-4194-86C5-B24F7AB42103.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7D4C5730-B701-4008-B2CB-EA61B5050542.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7E8792E7-4E8D-4746-8E6E-B562AD68EDC5.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8568717B-F373-481A-B192-EFC66F779761.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS875C2B41-CB5A-48E7-A93E-38EBD948D827.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8BF6FEB3-3EA9-4FBB-8456-639C8681A507.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8C97F668-3326-4B65-B79F-1DF6D08796E2.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS94FCAB95-B09A-41D7-89D5-C1247A3ED055.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS94167F22-63C6-4FBB-81EF-0D33819E9EDA.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9C9347B7-3AE3-4178-86A8-46764C7CDAED.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9D377098-3C61-4361-8D9F-AB3D892D7EAF.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA0957628-9870-4059-BD89-446E9B99E858.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA1719B14-C87C-4F64-91F6-EAA041F18428.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA37B5E0A-B6D3-4FAB-A053-AC0FC2A8460F.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA8C1391A-211C-4674-AB7B-7930FE7CDEA0.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAD525838-40C9-453C-BDEF-1879CD720BBF.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB3EEE3C7-98FD-4341-8207-1F018F3FE9E6.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB3D111B4-B8A3-4B69-A94B-8CC9ED0CEFCB.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB661856A-EE98-4FB9-8E4C-D03C34180E6D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB92EB59F-77CB-47AC-93CF-5CBE78F385ED.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBD83837E-546E-4E6C-B86D-51E4941039C8.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD0E6DC46-C328-47CA-89A5-2D0287354E67.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD6665368-D776-4F11-B420-9C90357D7C00.tmp"
Mon 15 Dec 2008 65,536 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD7D798F8-F779-410C-9465-30AB3D88069D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDDD91020-7DBC-4D41-A437-704BCDBA953E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDF700C9B-A150-49E4-B7E8-40C015A7BFCA.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE20DC335-3C16-4C76-8F90-1A73A214B223.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE818CF9A-DD37-43B9-9901-90444950187E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE9917336-D72E-4E3F-8DDD-D6567F3F8866.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEACA92C1-0693-4879-9D03-9CF965DC5969.tmp"
Mon 15 Dec 2008 65,536 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEADC54D7-3203-4E87-9512-0CAACD74E015.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEECD5B27-0F9C-49DD-B840-C8AB8D09838E.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEFF9E048-5FF1-4636-955D-C4119FAFD5BB.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEF6FD132-13E4-4F0F-8A4E-B0279A754CC9.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF3876639-D444-4076-A48A-98B91A3E166D.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF4C2220A-740E-4A14-BE9E-7E8A5FFB12CF.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF8F18346-5179-42E8-A76F-18C5EA3F4363.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFE656526-334F-4EAF-90C9-01A14C83F362.tmp"
Mon 15 Dec 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFF9E3ED4-4446-4DDB-9F9C-5C13337ABBF2.tmp"
Wed 10 Oct 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Wed 10 Oct 2007 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"

Finished!

#4 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:11:26 AM

Posted 16 December 2008 - 07:01 PM

This should restore your connection.

Run Hijackthis again, click scan, and Put a checkmark next to each of the lines listed below. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>



Reboot and you should have your connection back.



Now we need to run Combofix.

Please download ComboFix from one of these locations:

Link 1
Link 2
Link 3

Important!
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert.
It is intended by its creator to be used under the guidance and supervision of an Malware Removal Expert, not for private use.
Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.



Make sure that you save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#5 MaxwellHouse

MaxwellHouse
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 16 December 2008 - 11:49 PM

Hi Sam - I've taken the first step and regained my connection. I've also downloaded Combofix and attempted to follow the attached instructions, but when Combofix attempts to download Windows Recovery Console it errors and says I don't have an active internet connection. This clearly is not the case, as I'm able to access the internet normally (the initial problem appears to be fixed btw).

Additionally, I've run a scan using my virus protection software, and it came across 3 viruses and 1 spyware. Here's what it says (maybe we can address this once the Combofix issue is taken care of):

Result: 4 malware found
Net-Worm.Win32.Koobface.cr (virus)
C:\WINDOWS\bolivar30.exe
Trojan.Win32.Agent.atpj (virus)
C:\SDFix\backups\backups.zip\backups\tinyproxy.exe
TrackingCookie.Advertising (Tracking cookie)
Action: quarantined
Net-Worm.Win32.Koobface (virus)
Action: quarantined

Thanks!!

#6 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:11:26 AM

Posted 17 December 2008 - 10:11 AM

You can install the recovery console without going through Combofix. Here is a tutorial.
http://www.bleepingcomputer.com/tutorials/how-to-install-the-windows-xp-recovery-console/

Once you get the recovery console installed, proceed with running Combofix.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#7 MaxwellHouse

MaxwellHouse
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 17 December 2008 - 05:39 PM

Hi Sam,

Can't do that either :thumbsup:. Says the current version of Windows on my computer is newer than the one on the install disc and won't install Windows Recovery Console.

So what now?

#8 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:11:26 AM

Posted 18 December 2008 - 10:04 AM

Click Start -> Run -> %windir%\i386\winnt32.exe /cmdcons

Any luck?
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#9 MaxwellHouse

MaxwellHouse
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 18 December 2008 - 10:23 PM

None - Is it advisable to use Combofix without the WRC? Otherwise, is there any other program we can use where WRC is not required?

Thanks,

#10 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:11:26 AM

Posted 19 December 2008 - 11:16 AM

Combofix gives us our best option to fixing your issues. Let's try one more method for you.

Go to this page and download the the setup disk program.
http://www.microsoft.com/downloads/details...;displaylang=en

Save it to your desktop right next to Combofix.

Posted Image


Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.

Please do not reboot your machine until we have reviewed the log.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#11 MaxwellHouse

MaxwellHouse
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 20 December 2008 - 11:51 AM

Fantastic :thumbsup:

Success at last! Here's the Combofix log:

ComboFix 08-12-16.03 - Mike 2008-12-20 9:18:58.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3071.2473 [GMT -7:00]
Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mike\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\f49f4daa.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games


((((((((((((((((((((((((( Files Created from 2008-11-20 to 2008-12-20 )))))))))))))))))))))))))))))))
.

2008-12-18 19:36 . 2008-12-18 20:15 <DIR> d-------- C:\XPSP2
2008-12-18 19:35 . 2008-12-18 20:11 <DIR> d-------- C:\XPCD
2008-12-17 15:32 . 2008-12-20 09:41 <DIR> d-------- c:\documents and settings\Avery
2008-12-17 15:05 . 2008-12-17 21:36 1,393 --a------ c:\windows\imsins.BAK
2008-12-16 20:01 . 2008-12-16 20:01 30,856 --a------ c:\windows\system32\drivers\fsbts.sys
2008-12-16 19:52 . 2008-12-16 19:52 <DIR> d-------- c:\documents and settings\Mike\Application Data\F-Secure
2008-12-16 19:49 . 2008-09-23 06:35 79,904 --a------ c:\windows\system32\drivers\fsdfw.sys
2008-12-15 22:53 . 2008-12-15 22:53 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-12-15 22:49 . 2008-12-15 22:50 <DIR> d-------- c:\windows\ERUNT
2008-12-15 22:37 . 2008-12-15 23:15 <DIR> d-------- C:\SDFix
2008-12-14 16:45 . 2008-12-14 16:45 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-14 16:38 . 2008-12-14 16:45 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-14 16:22 . 2008-12-14 16:25 <DIR> d-------- c:\documents and settings\Mike\.SunDownloadManager
2008-12-14 15:39 . 2008-12-14 15:39 <DIR> d-------- C:\rsit
2008-12-14 15:08 . 2008-12-14 15:08 <DIR> d-------- c:\program files\CCleaner
2008-12-13 20:37 . 2008-12-13 20:39 1,349 ---h----- c:\windows\f49f4d98.dat
2008-12-13 20:35 . 2008-12-13 20:35 1 ---h----- c:\windows\fm123.dat
2008-12-12 17:16 . 2008-07-12 08:18 3,851,784 --a------ c:\windows\system32\D3DX9_39.dll
2008-12-12 17:16 . 2008-07-12 08:18 1,493,528 --a------ c:\windows\system32\D3DCompiler_39.dll
2008-12-12 17:16 . 2008-07-31 10:40 509,448 --a------ c:\windows\system32\XAudio2_2.dll
2008-12-12 17:16 . 2008-07-12 08:18 467,984 --a------ c:\windows\system32\d3dx10_39.dll
2008-12-12 17:16 . 2008-07-31 10:41 238,088 --a------ c:\windows\system32\xactengine3_2.dll
2008-12-12 17:16 . 2008-07-31 10:41 68,616 --a------ c:\windows\system32\XAPOFX1_1.dll
2008-11-26 08:03 . 2008-11-26 08:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-26 08:02 . 2008-11-26 08:03 <DIR> d-------- c:\program files\QuickTime
2008-11-21 20:58 . 2008-11-21 20:58 <DIR> d-------- c:\program files\Uniblue
2008-11-21 20:58 . 2008-11-21 20:58 <DIR> d-------- c:\documents and settings\Mike\Application Data\Uniblue
2008-11-21 20:57 . 2008-11-21 20:58 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-20 16:00 --------- d-----w c:\documents and settings\Mike\Application Data\Azureus
2008-12-20 04:47 --------- d-----w c:\program files\Steam
2008-12-19 20:44 --------- d-----w c:\program files\Shaw Secure
2008-12-17 02:49 --------- d-----w c:\documents and settings\All Users\Application Data\F-Secure
2008-12-17 02:48 --------- d-----w c:\documents and settings\All Users\Application Data\fssg
2008-12-14 23:45 --------- d-----w c:\program files\Java
2008-12-12 04:18 --------- d-----w c:\program files\Electronic Arts
2008-12-03 00:41 --------- d-----w c:\program files\PokerStars.NET
2008-11-29 17:17 30,640 -c--a-w c:\documents and settings\Mike\Application Data\GDIPFONTCACHEV1.DAT
2008-11-27 05:15 --------- d-----w c:\program files\Soulseek
2008-11-26 15:04 --------- d-----w c:\program files\iTunes
2008-11-26 15:03 --------- d-----w c:\program files\iPod
2008-11-26 15:03 --------- d-----w c:\program files\Common Files\Apple
2008-11-26 03:20 --------- d-----w c:\program files\Common Files\Adobe
2008-11-26 01:28 --------- d-----w c:\program files\Safari
2008-11-22 04:45 --------- d-----w c:\program files\Azureus
2008-11-15 04:12 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-15 04:11 --------- d-----w c:\program files\Sonic
2008-11-15 04:11 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-15 03:21 --------- d-----w c:\program files\WinAVI Video Converter
2008-11-15 02:42 --------- d-----w c:\program files\Common Files\Sonic Shared
2008-11-14 06:04 --------- d-----w c:\documents and settings\Mike\Application Data\Video DVD Maker FREE
2008-11-01 16:07 --------- d-----w c:\program files\MSECache
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 14:13 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-10-23 14:13 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-23 14:13 22,328 ----a-w c:\documents and settings\Mike\Application Data\PnkBstrK.sys
2008-10-23 14:13 2,250,024 ----a-w c:\windows\system32\pbsvc.exe
2008-10-23 14:13 107,832 ----a-w c:\windows\system32\PnkBstrB.exe
2008-10-23 13:57 --------- d-----w c:\program files\Ubisoft
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 05:04 --------- d-----w c:\documents and settings\Mike\Application Data\IGN_DLM
2008-10-23 03:03 --------- d-----w c:\program files\MUSICMATCH
2008-10-23 03:03 --------- d-----w c:\documents and settings\Mike\Application Data\My Games
2008-10-16 21:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 21:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 21:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 21:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 21:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 21:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 21:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 21:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-10-02 16:07 453,152 ----a-w c:\windows\system32\NVUNINST.EXE
2008-09-30 23:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-21 20:30 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-15 17:51 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-11-15 17:51 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-11-15 17:51 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-11-15 17:51 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-11-15 17:51 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"igndlm.exe"="c:\program files\IGN\Download Manager\dlm.exe" [2008-08-01 1103216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-10 185896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="c:\windows\system32\nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-14 136600]
"F-Secure Manager"="c:\program files\Shaw Secure\Common\FSM32.EXE" [2008-09-23 182936]
"F-Secure TNB"="c:\program files\Shaw Secure\FSGUI\TNBUtil.exe" [2008-09-23 957024]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\System32\ctmp3.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digimax Viewer 2.1.lnk]
backup=c:\windows\pss\Digimax Viewer 2.1.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Nintendo Wi-Fi USB Connector Registration Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
backup=c:\windows\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdwareAlert
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize2 Reminder

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a--c--- 2007-03-09 10:09 63712 c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-11-07 14:16 111936 c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
--a--c--- 2003-08-29 04:59 122880 c:\windows\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 17:12 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
--a------ 2002-04-03 00:01 135264 c:\program files\Creative\SBLive\Diagnostics\diagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
--a------ 2008-07-22 11:34 2772992 c:\program files\Electronic Arts\EADM\Core.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
--a------ 2006-10-30 10:01 392832 c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure Manager]
--a------ 2008-09-23 06:37 182936 c:\program files\Shaw Secure\Common\FSM32.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure TNB]
--a------ 2008-09-23 06:37 957024 c:\program files\Shaw Secure\FSGUI\tnbutil.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
--a------ 2008-08-01 12:36 1103216 c:\program files\IGN\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
-----c--- 2003-05-16 08:50 19968 c:\windows\LOGI_MWX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 17:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-10-07 12:33 13574144 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-10-07 12:33 86016 c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-10-07 12:33 1630208 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
-----c--- 2003-08-26 18:47 204800 c:\program files\Dell\Media Experience\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDUiP6220DMon]
--a--c--- 2005-05-06 17:17 69632 c:\program files\Canon\Memory Card Utility\iP6220D\PDUiP6220DMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-12-11 21:00 1410296 c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-03-10 16:48 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
-----c--- 2000-05-11 00:00 90112 c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeatherEye]
--a------ 2008-05-30 13:45 4501912 c:\program files\TheWeatherNetwork\WeatherEye\WeatherEye.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WebrootSpySweeperService"=2 (0x2)
"spkrmon"=2 (0x2)
"PnkBstrA"=2 (0x2)
"NVSvc"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"FSMA"=2 (0x2)
"FSDFWD"=3 (0x3)
"FSAUA"=3 (0x3)
"F-Secure Gatekeeper Handler Starter"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"Boonty Games"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"PnkBstrB"=2 (0x2)
"Bonjour Service"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Abacast\\Abaclient.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Soulseek-Test\\slsk.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6881:TCP"= 6881:TCP:Torrents
"6882:TCP"= 6882:TCP:torrents
"6883:TCP"= 6883:TCP:torrents
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"28910:TCP"= 28910:TCP:nintendo wifi
"29900:TCP"= 29900:TCP:nintendo wifi
"29901:TCP"= 29901:TCP:nintendo wifi
"29920:TCP"= 29920:TCP:nintendo wifi
"80:TCP"= 80:TCP:nintendo wifi
"11119:TCP"= 11119:TCP:Azureus
"6884:TCP"= 6884:TCP:Torrents
"6885:TCP"= 6885:TCP:Torrents
"6886:TCP"= 6886:TCP:Torrents
"6887:TCP"= 6887:TCP:Torrents
"6888:TCP"= 6888:TCP:Torrents
"6889:TCP"= 6889:TCP:Torrents
"8547:TCP"= 8547:TCP:Soulseek
"49152:TCP"= 49152:TCP:Azureus
"49152:UDP"= 49152:UDP:Azureus

R0 fsbts;fsbts;c:\windows\system32\Drivers\fsbts.sys [2008-12-16 30856]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-12-16 79904]
R1 F-Secure HIPS;F-Secure HIPS Driver;\??\c:\program files\Shaw Secure\HIPS\drivers\fshs.sys [2008-12-16 66720]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\c:\program files\Shaw Secure\Anti-Virus\minifilter\fsgk.sys [2008-12-16 72288]
R3 FSORSPClient;F-Secure ORSP Client;"c:\program files\Shaw Secure\ORSP Client\fsorsp.exe" [2008-12-16 55904]
S4 F-Secure Filter;F-Secure File System Filter;\??\c:\program files\Shaw Secure\Anti-Virus\Win2K\FSfilter.sys [2008-12-16 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;\??\c:\program files\Shaw Secure\Anti-Virus\Win2K\FSrec.sys [2008-12-16 25184]
.
Contents of the 'Scheduled Tasks' folder

2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-12-20 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\SHAWSE~1\ANTI-V~1\fsav.exe [2008-09-23 06:35]
.
- - - - ORPHANS REMOVED - - - -

Notify-AtiExtEvent - (no file)
MSConfigStartUp-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
MSConfigStartUp-MimBoot - c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe
MSConfigStartUp-News Service - c:\program files\Shaw Secure\FSGUI\ispnews.exe
MSConfigStartUp-SpySweeper - c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe
MSConfigStartUp-Comrade - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.ca/
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe -
LSP: c:\program files\Shaw Secure\FSPS\program\FSLSP.DLL

c:\windows\system32\unicows.dll - c:\windows\Downloaded Program Files\ImageUploader3.ocx
O16 -: {29C8B1AC-073B-46AC-A077-5114D4C3BF0C}
hxxp://photoshare.shaw.ca/include/ImageUploader.cab
c:\windows\Downloaded Program Files\ImageUploader3.inf

c:\windows\system32\msvcr71.dll - c:\program files\ATI Technologies\ATI.ACE\MFC71.dll
c:\windows\Downloaded Program Files\MultiSelectComboBox.dll
O16 -: {4989312D-58CF-11D5-A7D7-00E02911103E}
hxxp://abmls.mlxchange.com/Control/MultiSelectComboBox.cab
c:\windows\Downloaded Program Files\MultiSelectComboBoxCab.inf

c:\windows\system32\msvcr71.dll - c:\program files\ATI Technologies\ATI.ACE\MFC71.dll
c:\windows\Downloaded Program Files\MLXClientUtils.dll
O16 -: {6FD482A3-7B57-438B-B040-52CAA30147EE}
hxxp://abmls.mlxchange.com/Control/MLXClientUtils.cab
c:\windows\Downloaded Program Files\MLXClientUtilsCab.inf

c:\windows\system32\msvcr71.dll - c:\program files\ATI Technologies\ATI.ACE\MFC71.dll
c:\windows\system32\missouri.dll
c:\windows\system32\GeacView.dll
c:\windows\Downloaded Program Files\GeacRevw.ocx
O16 -: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E}
hxxp://abmls.mlxchange.com/Control/IRCSharc.cab
c:\windows\Downloaded Program Files\IRCSharcCab.inf
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\xb5lm38r.default\
FF - prefs.js: browser.startup.homepage - google.ca
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 9090
FF - prefs.js: network.proxy.type - 1
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-20 09:44:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(640)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll

- - - - - - - > 'lsass.exe'(696)
c:\program files\Shaw Secure\FSPS\program\FSLSP.DLL
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll

- - - - - - - > 'csrss.exe'(616)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Shaw Secure\Anti-Virus\fsgk32st.exe
c:\program files\Shaw Secure\Common\FSMA32.EXE
c:\program files\Shaw Secure\Anti-Virus\fsgk32.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Shaw Secure\Common\FSMB32.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Shaw Secure\Common\FCH32.EXE
c:\windows\system32\MsPMSPSv.exe
c:\program files\Shaw Secure\Anti-Virus\fssm32.exe
c:\program files\Shaw Secure\Common\FAMEH32.EXE
c:\program files\Shaw Secure\Anti-Virus\fsqh.exe
c:\program files\Shaw Secure\FSPC\fspc.exe
c:\program files\Shaw Secure\FSAUA\program\fsaua.exe
c:\program files\Shaw Secure\FWES\program\fsdfwd.exe
c:\program files\Shaw Secure\FSAUA\program\fsus.exe
c:\program files\Shaw Secure\Anti-Virus\fsav32.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\SHAWSE~1\FSGUI\fsguidll.exe
.
**************************************************************************
.
Completion time: 2008-12-20 9:47:46 - machine was rebooted [Mike]
ComboFix-quarantined-files.txt 2008-12-20 16:47:40

Pre-Run: 32,369,537,024 bytes free
Post-Run: 32,609,202,176 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut

358 --- E O F --- 2008-12-18 04:36:05

#12 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:11:26 AM

Posted 20 December 2008 - 01:16 PM

:thumbsup:


Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


How is your computer behaving now?
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#13 MaxwellHouse

MaxwellHouse
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 20 December 2008 - 06:07 PM

Computer appears to be functioning normally - thanks!

Here's the MBAM log:

Malwarebytes' Anti-Malware 1.31
Database version: 1526
Windows 5.1.2600 Service Pack 3

12/20/2008 4:05:45 PM
mbam-log-2008-12-20 (16-05-45).txt

Scan type: Quick Scan
Objects scanned: 56709
Time elapsed: 5 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\AdwareAlert\DataBaseNew.ref (Rogue.AdwareAlert) -> Quarantined and deleted successfully.

#14 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:11:26 AM

Posted 21 December 2008 - 09:10 AM

You are running an older version of Java. This can be a security risk so let's get you the latest version.
Upgrading Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 11.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 11".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u10-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.


===============



Just a few last things and you should be good to go! :)


Next, let's remove Combofix now that we're done with it and clean up a few other things.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK

  • Posted Image



==================



Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point left over from what we have just cleaned.

    You can find instructions on how to enable and reenable system restore here:

    Windows XP System Restore Guide

    Renable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

:thumbsup: :)
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#15 MaxwellHouse

MaxwellHouse
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 22 December 2008 - 05:22 PM

Thanks very much Sam!

Everything is working well.

Happy Holidays!! :thumbsup:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users