Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

AVG threat detected and about 100 IE windows


  • This topic is locked This topic is locked
8 replies to this topic

#1 jaybird2000

jaybird2000

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:01:08 PM

Posted 13 May 2009 - 05:11 AM

Computer seemed fine all day long yesterday then I went to sleep and when I woke up I had about 100 threats detected and a LOT of IE windows open to various ads AVG couldn't heal any of them.I opened task manager and ended the processes that i know where causing it but i know that won't get rid of them of course so if one of you very nice people could help me remove it i would be very very thankfull here the log




DDS (Ver_09-03-16.01) - NTFSx86
Run by Compaq_Owner at 5:00:09.71 on Wed 05/13/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
FW: Webroot Internet Security Essentials *disabled*
FW: COMODO Firewall *enabled*

============== Running Processes ===============


============== Pseudo HJT Report ===============

uStart Page = hxxp://www.toggle.com/en/index.php?rvs=hompag&d=79919181
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {d14996e2-dee8-4a2c-9e5b-b884e25a7747} - c:\windows\system32\redivegi.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Ask Toolbar BHO: {f0d4b231-da4b-4daf-81e4-dfee4931a4aa} - c:\program files\asksbar\bar\1.bin\ASKSBAR.DLL
TB: Ask Toolbar: {f0d4b239-da4b-4daf-81e4-dfee4931a4aa} - c:\program files\asksbar\bar\1.bin\ASKSBAR.DLL
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [prnet] "c:\windows\system32\prnet.tmp"
uRun: [net] "c:\windows\system32\net.net"
uRun: [ptidle] "c:\documents and settings\compaq_owner\application data\ptidle\ptidle.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
mRun: [AVG8_TRAY] "c:\progra~1\avg\avg8\avgtray.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [VTTimer] "c:\windows\system32\VTTimer.exe"
mRun: [COMODO SafeSurf] "c:\program files\comodo\safesurf\cssurf.exe" -s
mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [COMODO Internet Security] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] "c:\windows\system32\nwiz.exe" /install
mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [BootSkin Startup Jobs] "c:\progra~1\stardock\wincus~1\bootskin\BootSkin.exe" /StartupJobs
mRun: [RDListener] "c:\program files\registry defense\RDListener.exe"
mRun: [pehekoguwe] Rundll32.exe "c:\windows\system32\vebimayo.dll",s
mRun: [prnet] "c:\windows\system32\prnet.tmp"
mRun: [net] "c:\windows\system32\net.net"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1208046271638
DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} - hxxp://www.acclaim.com/cabs/acclaim_v4.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: WBSrv - c:\program files\alienguise\wbsrv.dll
AppInit_DLLs: c:\windows\system32\vebuzahu.dll,c:\windows\system32\pidizowi.dll,c:\windows\system32\juhadove.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - c:\program files\stardock\object desktop\iconpackager\iprepair.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli c:\windows\system32\vebuzahu.dll c:\windows\system32\pidizowi.dll c:\windows\system32\juhadove.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\5lemim38.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.toadtastic.com
FF - component: c:\documents and settings\compaq_owner\application data\mozilla\firefox\profiles\5lemim38.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\FFAlert.dll
FF - component: c:\documents and settings\compaq_owner\application data\mozilla\firefox\profiles\5lemim38.default\extensions\piclens@cooliris.com\components\piclensstub.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\compaq_owner\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\opera\program\plugins\npdivx32.dll

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-05-12 18:31 110,952 a------- c:\windows\system32\net.net
2009-05-12 18:16 <DIR> --d----- c:\docume~1\compaq~1\applic~1\ptidle
2009-05-12 18:15 165,376 a------- c:\windows\system32\prnet.tmp
2009-05-12 17:39 287 a------- c:\windows\EReg072.dat
2009-05-12 17:37 299,008 a------- c:\windows\uninst.exe
2009-05-12 00:30 <DIR> --d----- C:\nDoors
2009-05-11 17:16 <DIR> --d----- c:\program files\DNA
2009-05-11 17:16 <DIR> --d----- c:\docume~1\compaq~1\applic~1\DNA
2009-05-10 23:45 <DIR> --d----- C:\Binaries
2009-05-10 23:43 1,553,272 a------- c:\windows\WRSetup.dll
2009-05-10 23:43 <DIR> --d----- c:\program files\Webroot
2009-05-10 23:43 <DIR> --d----- c:\docume~1\compaq~1\applic~1\Webroot
2009-05-10 23:43 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Webroot
2009-05-10 22:21 <DIR> --d----- c:\docume~1\compaq~1\applic~1\RegistryDefense
2009-05-10 22:21 <DIR> --d----- c:\program files\Registry Defense
2009-05-07 00:19 258,352 a------- c:\windows\system32\unicows.dll
2009-05-06 18:47 161,792 a------- c:\windows\SWREG.exe
2009-05-06 18:47 98,816 a------- c:\windows\sed.exe
2009-05-01 03:30 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{B98A2B83-8BB0-42E7-AA1D-D6FA6E7C8F31}
2009-05-01 03:08 <DIR> --d----- c:\docume~1\compaq~1\applic~1\Stardock
2009-05-01 03:07 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{62902F53-D725-44F9-B385-979CC0E00E8A}
2009-05-01 03:07 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Stardock
2009-04-30 00:14 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Age of Empires 3
2009-04-29 23:54 2,297,552 a------- c:\windows\system32\d3dx9_26.dll
2009-04-28 15:06 118,784 a------- c:\windows\DiabUnin.exe
2009-04-28 15:06 2,829 a------- c:\windows\DiabUnin.pif
2009-04-28 15:06 <DIR> --d----- c:\program files\Diablo
2009-04-28 15:06 5,967 a------- c:\windows\DiabUnin.dat
2009-04-21 01:42 163,712 a------- c:\windows\system32\drivers\vidstub.sys
2009-04-21 01:42 <DIR> --d----- c:\program files\Stardock
2009-04-15 23:59 <DIR> --d----- C:\Makaron
2009-04-15 23:32 <DIR> --d----- C:\Dreamcast
2009-04-13 21:19 41,808 a------- c:\windows\system32\xfcodec.dll
2009-04-13 10:24 <DIR> --d----- c:\program files\Counter-Strike 1.6

==================== Find3M ====================

2009-05-02 08:19 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-02 08:18 325,896 a------- c:\windows\system32\drivers\avgldx86.sys
2009-05-02 08:18 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-04-05 21:38 410,984 a------- c:\windows\system32\deploytk.dll
2009-03-26 16:49 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 16:49 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-03-06 09:44 283,648 a------- c:\windows\system32\pdh.dll
2009-03-02 19:18 826,368 a------- c:\windows\system32\wininet.dll
2009-02-27 13:48 155,384 a------- c:\windows\system32\guard32.dll
2009-02-20 13:09 78,336 a------- c:\windows\system32\ieencode.dll
2009-02-12 18:31 48,640 a--sh--- c:\windows\system32\vebimayo.dll
2009-02-12 18:25 48,640 a--sh--- c:\windows\system32\rigewulu.dll
2009-02-12 18:16 48,640 a--sh--- c:\windows\system32\ragehage.dll
2008-08-23 05:43 24 a------- c:\documents and settings\compaq_owner\jagex_runescape_preferences.dat

============= FINISH: 5:01:51.50 ===============











P.S I just wanted to tell you guys i think its awesome how you guys help people for free can't thank you all enough for your help =]

Attached Files



BC AdBot (Login to Remove)

 


#2 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:08:08 PM

Posted 13 May 2009 - 06:32 AM

Hi,

* Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • In case you already used MBAM previously, please update it before proceeding with the scan. To do this, click the "Update" tab and click the "Check For updates" button.
  • Once the program has loaded and updates were downloaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply along with a fresh HijackThis log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 jaybird2000

jaybird2000
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:01:08 PM

Posted 13 May 2009 - 07:25 AM

Done.Heres the MalwareBytes Log....


Malwarebytes' Anti-Malware 1.36
Database version: 2121
Windows 5.1.2600 Service Pack 2

5/13/2009 7:13:29 AM
mbam-log-2009-05-13 (07-13-29).txt

Scan type: Quick Scan
Objects scanned: 88683
Time elapsed: 21 minute(s), 52 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 6
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 17

Memory Processes Infected:
C:\WINDOWS\system32\net.net (Trojan.Downloader) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d14996e2-dee8-4a2c-9e5b-b884e25a7747} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d14996e2-dee8-4a2c-9e5b-b884e25a7747} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.
KHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\prnet (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pehekoguwe (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\net (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\net (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prnet (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\prnet (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ptidle (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Compaq_Owner\Application Data\ptidle (Trojan.Downloader) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\vebimayo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\net.net (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\prnet.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\ptidle\ptidle.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ragehage.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rigewulu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\nwrseacxom.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\ovfsthcpcrjqvnsu.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\ovfsthrprnuobwtb.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\ovfsthswbbpevvmb.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\ovfsthtsxodspqsl.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\csnemrowax.tmp (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\rasesnet.tmp (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\prun.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\ptidle\ptidle.exe3af (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\ovfsthapeobvxsfx.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\temp\ovfsthdeqxnpmbyx.tmp (Trojan.Agent) -> Quarantined and deleted successfully.


and heres the HijackThis Log



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:20:32 AM, on 5/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Registry Defense\RDListener.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toggle.com/en/index.php?rvs=hompag&d=79919181
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [AVG8_TRAY] "C:\PROGRA~1\AVG\AVG8\avgtray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [VTTimer] "C:\WINDOWS\system32\VTTimer.exe"
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [RDListener] "C:\Program Files\Registry Defense\RDListener.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-2081054606-3104491657-858206439-1009\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1208046271638
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\vebuzahu.dll,C:\WINDOWS\system32\pidizowi.dll,C:\WINDOWS\system32\juhadove.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

--
End of file - 8070 bytes

#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:08:08 PM

Posted 13 May 2009 - 07:39 AM

Hi,

This is A LOT better already. Please uninstall Registry Defense and Ask Toolbar since both are unwanted.

Reboot afterwards.

* Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the log from ComboFix in your next reply.

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix..This because Security Software may see some components ComboFix uses (prep.com for example) as suspicious and blocks the tool, or even deletes it. Please visit HERE if you don't know how.

Edited by miekiemoes, 13 May 2009 - 07:39 AM.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 jaybird2000

jaybird2000
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:01:08 PM

Posted 13 May 2009 - 10:41 AM

ComboFix 09-05-12.06 - Compaq_Owner 05/13/2009 10:09.4 - NTFSx86
Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
FW: COMODO Firewall *enabled*
FW: PC Tools Firewall Plus *enabled*
FW: Webroot Internet Security Essentials *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Compaq_Owner\Local Settings\Temporary Internet Files\fbk.sts

.
((((((((((((((((((((((((( Files Created from 2009-04-13 to 2009-05-13 )))))))))))))))))))))))))))))))
.

2009-05-12 22:39 . 2009-05-12 22:39 287 ----a-w c:\windows\EReg072.dat
2009-05-12 22:37 . 2009-05-12 22:37 -------- d-----w c:\program files\Electronic Arts
2009-05-12 22:37 . 1998-05-01 18:39 299008 ----a-w c:\windows\uninst.exe
2009-05-12 10:09 . 2009-05-12 10:09 -------- d-----w c:\documents and settings\Compaq_Owner\Application Data\InstallShield
2009-05-12 05:30 . 2009-05-12 05:56 -------- d-----w C:\nDoors
2009-05-11 22:16 . 2009-05-11 22:16 -------- d-----w c:\documents and settings\Compaq_Owner\Local Settings\Application Data\DNA
2009-05-11 22:16 . 2009-05-11 22:16 -------- d-----w c:\program files\DNA
2009-05-11 22:16 . 2009-05-12 08:08 -------- d-----w c:\documents and settings\Compaq_Owner\Application Data\DNA
2009-05-11 04:45 . 2009-05-11 04:45 -------- d-----w C:\Binaries
2009-05-11 04:43 . 2008-11-13 22:11 1553272 ----a-w c:\windows\WRSetup.dll
2009-05-11 04:43 . 2009-05-11 04:43 -------- d-----w c:\documents and settings\Compaq_Owner\Application Data\Webroot
2009-05-11 04:43 . 2009-05-11 05:19 -------- d-----w c:\documents and settings\All Users\Application Data\Webroot
2009-05-11 04:43 . 2009-05-11 04:43 -------- d-----w c:\program files\Webroot
2009-05-11 03:21 . 2009-05-11 03:33 -------- d-----w c:\documents and settings\Compaq_Owner\Application Data\RegistryDefense
2009-05-07 05:19 . 2005-05-11 01:54 258352 ----a-w c:\windows\system32\unicows.dll
2009-05-01 08:30 . 2009-05-01 08:30 -------- dc-h--w c:\documents and settings\All Users\Application Data\{B98A2B83-8BB0-42E7-AA1D-D6FA6E7C8F31}
2009-05-01 08:08 . 2009-05-01 08:11 -------- d-----w c:\documents and settings\Compaq_Owner\Application Data\Stardock
2009-05-01 08:07 . 2009-05-01 08:07 -------- d-----w c:\documents and settings\All Users\Application Data\Stardock
2009-04-30 05:14 . 2009-04-30 05:14 -------- d-----w c:\documents and settings\All Users\Application Data\Age of Empires 3
2009-04-30 04:54 . 2005-05-26 20:34 2297552 ----a-w c:\windows\system32\d3dx9_26.dll
2009-04-28 20:06 . 2009-04-28 20:06 2829 ----a-w c:\windows\DiabUnin.pif
2009-04-28 20:06 . 2009-04-28 20:06 118784 ----a-w c:\windows\DiabUnin.exe
2009-04-28 20:06 . 2009-05-09 13:29 -------- d-----w c:\program files\Diablo
2009-04-28 20:06 . 2009-04-30 09:23 5967 ----a-w c:\windows\DiabUnin.dat
2009-04-21 06:42 . 2009-04-21 06:43 163712 ----a-w c:\windows\system32\drivers\vidstub.sys
2009-04-21 06:42 . 2009-05-13 14:56 -------- d-----w c:\program files\Stardock
2009-04-16 04:59 . 2009-04-16 05:17 -------- d-----w C:\Makaron
2009-04-16 04:32 . 2009-04-16 04:40 -------- d-----w C:\Dreamcast
2009-04-14 05:08 . 2009-04-14 05:08 -------- d-----w c:\documents and settings\LocalService\Application Data\Xfire
2009-04-14 02:19 . 2009-04-14 02:19 41808 ----a-w c:\windows\system32\xfcodec.dll
2009-04-13 15:24 . 2009-04-13 15:26 -------- d-----w c:\program files\Counter-Strike 1.6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 11:48 . 2009-04-01 09:22 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-12 20:34 . 2009-01-14 15:38 -------- d-----w c:\program files\Cheat Engine
2009-05-12 10:09 . 2004-08-09 08:51 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-11 21:57 . 2009-03-07 21:43 -------- d-----w c:\program files\MythwarII
2009-05-09 03:23 . 2008-11-18 09:49 -------- d-----w c:\program files\World of Warcraft
2009-05-06 05:36 . 2008-08-15 07:42 -------- d-----w c:\program files\Tales of Pirates Online
2009-05-02 13:19 . 2008-05-05 22:59 11952 ----a-w c:\windows\system32\avgrsstx.dll
2009-05-02 13:18 . 2008-05-05 22:59 325896 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-02 13:18 . 2008-05-05 22:59 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-30 04:46 . 2008-05-13 00:55 -------- d-----w c:\program files\Microsoft Games
2009-04-21 06:42 . 2008-08-24 11:16 -------- d-----w c:\program files\Common Files\Stardock
2009-04-18 01:40 . 2008-10-31 02:47 -------- d-----w c:\program files\Xfire
2009-04-06 20:32 . 2009-04-01 09:22 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 20:32 . 2009-04-01 09:22 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-06 02:39 . 2009-04-06 02:39 -------- d-----w c:\program files\Trend Micro
2009-04-06 02:38 . 2009-04-06 02:39 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-06 02:38 . 2004-08-09 06:12 -------- d-----w c:\program files\Java
2009-04-02 01:12 . 2008-05-05 22:59 -------- d-----w c:\program files\AVG
2009-04-01 21:11 . 2008-08-22 14:05 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-03-31 05:22 . 2008-12-31 07:19 -------- d-----w c:\program files\SUPERAntiSpyware
2009-03-31 05:16 . 2008-05-05 23:02 -------- d-----w c:\program files\SpywareBlaster
2009-03-30 21:43 . 2009-03-24 17:27 -------- d-----w c:\program files\Microsoft
2009-03-30 21:42 . 2009-03-27 02:32 -------- d-----w c:\program files\MagicISO
2009-03-27 02:00 . 2009-03-27 02:00 -------- d-----w c:\program files\nullDC
2009-03-24 17:41 . 2008-06-13 02:11 -------- d-----w c:\program files\Windows Live
2009-03-24 17:41 . 2009-03-24 17:41 -------- d-----w c:\program files\Microsoft Sync Framework
2009-03-24 17:37 . 2009-03-24 17:37 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-03-24 17:04 . 2009-03-24 17:04 -------- d-----w c:\program files\Common Files\Windows Live
2009-03-22 18:58 . 2009-03-22 18:58 -------- d-----w c:\program files\Ventrilo
2009-03-22 18:57 . 2008-12-31 07:06 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-19 08:04 . 2009-03-19 08:04 -------- d-----w c:\program files\GamersFirst
2009-03-16 16:59 . 2004-08-09 06:51 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-16 16:53 . 2008-05-11 12:35 -------- d-----w c:\program files\SystemRequirementsLab
2009-03-06 14:44 . 2004-08-09 04:28 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-09 04:28 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-27 18:53 . 2009-01-13 09:48 24336 ----a-w c:\windows\system32\drivers\cmdhlp.sys
2009-02-27 18:48 . 2009-01-13 09:48 155384 ----a-w c:\windows\system32\guard32.dll
2009-02-27 18:48 . 2009-01-13 09:48 110992 ----a-w c:\windows\system32\drivers\cmdguard.sys
2009-02-20 18:09 . 2004-08-09 04:28 78336 ----a-w c:\windows\system32\ieencode.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-07_00.00.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-13 15:16 . 2009-05-13 15:16 16384 c:\windows\temp\Perflib_Perfdata_348.dat
+ 2008-11-12 21:02 . 2008-11-12 21:02 31088 c:\windows\system32\wrLZMA.dll
+ 2008-11-12 21:02 . 2008-11-12 21:02 16240 c:\windows\system32\SsiEfr.exe
- 2008-04-13 00:27 . 2007-07-27 14:41 26488 c:\windows\system32\spupdsvc.exe
+ 2008-04-13 00:27 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2004-08-09 04:28 . 2004-08-04 19:00 55808 c:\windows\system32\secur32.dll
+ 2004-08-09 04:28 . 2009-02-03 20:08 55808 c:\windows\system32\secur32.dll
+ 2008-04-11 23:34 . 2009-02-06 16:54 35328 c:\windows\system32\sc.exe
- 2004-08-09 04:28 . 2008-12-20 23:15 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-09 04:28 . 2009-05-08 23:31 63860 c:\windows\system32\perfc009.dat
- 2004-08-09 04:28 . 2009-03-16 16:26 63860 c:\windows\system32\perfc009.dat
+ 2004-08-09 05:41 . 2008-06-12 14:16 91648 c:\windows\system32\mtxoci.dll
+ 2004-08-09 04:28 . 2008-06-12 14:16 66560 c:\windows\system32\mtxclu.dll
- 2004-08-09 04:28 . 2006-03-01 19:42 66560 c:\windows\system32\mtxclu.dll
+ 2007-08-13 22:54 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
- 2007-08-13 22:54 . 2008-12-20 23:15 52224 c:\windows\system32\msfeedsbs.dll
- 2004-08-09 05:41 . 2004-08-04 19:00 58880 c:\windows\system32\msdtclog.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 58880 c:\windows\system32\msdtclog.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 27648 c:\windows\system32\jsproxy.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
+ 2007-08-13 22:39 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
- 2007-08-13 22:39 . 2008-12-19 09:10 13824 c:\windows\system32\ieudinit.exe
- 2004-08-09 04:28 . 2008-12-20 23:15 44544 c:\windows\system32\iernonce.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
+ 2004-08-09 04:28 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2004-08-09 04:28 . 2008-12-19 09:10 70656 c:\windows\system32\ie4uinit.exe
+ 2007-08-13 22:36 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
- 2007-08-13 22:36 . 2008-12-20 23:15 63488 c:\windows\system32\icardie.dll
+ 2008-11-12 21:02 . 2008-11-12 21:02 23152 c:\windows\system32\drivers\sshrmd.sys
+ 2008-11-12 21:02 . 2008-11-12 21:02 29808 c:\windows\system32\drivers\ssfs0bbc.sys
+ 2004-08-09 04:28 . 2009-02-03 20:08 55808 c:\windows\system32\dllcache\secur32.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 55808 c:\windows\system32\dllcache\secur32.dll
+ 2008-04-11 23:34 . 2009-02-06 16:54 35328 c:\windows\system32\dllcache\sc.exe
- 2004-08-09 04:28 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 91648 c:\windows\system32\dllcache\mtxoci.dll
- 2004-08-09 04:28 . 2006-03-01 19:42 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2004-08-09 04:28 . 2008-06-12 14:16 66560 c:\windows\system32\dllcache\mtxclu.dll
- 2008-04-13 01:18 . 2008-12-20 23:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-04-13 01:18 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2004-08-09 05:41 . 2004-08-04 19:00 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-13 01:18 . 2008-12-19 09:10 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2008-04-13 01:18 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2004-08-09 04:28 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\iernonce.dll
- 2004-08-09 04:28 . 2007-08-13 22:45 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
- 2004-08-09 04:28 . 2008-12-19 09:10 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-09 04:28 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
- 2008-04-13 01:18 . 2008-12-20 23:15 63488 c:\windows\system32\dllcache\icardie.dll
+ 2008-04-13 01:18 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
+ 2004-08-09 05:47 . 2009-05-11 15:12 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-09 05:47 . 2008-04-12 01:16 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-08-09 05:47 . 2009-05-11 15:12 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-08-09 05:47 . 2008-04-12 01:16 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-08-09 05:47 . 2009-05-11 15:12 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-13 00:31 . 2009-05-08 19:05 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-04-13 00:31 . 2009-05-08 19:05 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-04-13 00:31 . 2009-05-08 19:05 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-05-11 04:44 . 2009-05-11 04:44 10134 c:\windows\Installer\{3F5B6210-0903-4DC6-8034-8F488AA3A782}\ARPPRODUCTICON.exe
+ 2009-05-11 04:45 . 2009-05-11 04:45 10134 c:\windows\Installer\{32343DB6-9A52-40C9-87E4-5E7C79791C87}\ARPPRODUCTICON.exe
+ 2009-05-08 19:11 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-05-08 19:11 . 2008-12-19 09:10 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-05-08 19:11 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-05-08 19:11 . 2007-08-13 22:45 78336 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-05-08 19:11 . 2008-12-19 09:10 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-05-08 19:11 . 2008-12-20 23:15 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2009-05-13 15:17 . 2009-05-13 15:17 4722 c:\windows\temp\wrstemp\S-1-5-21-2081054606-3104491657-858206439-500.dat
+ 2009-05-13 15:17 . 2009-05-13 15:17 4950 c:\windows\temp\wrstemp\S-1-5-21-2081054606-3104491657-858206439-1009.dat
+ 2009-05-13 15:17 . 2009-05-13 15:17 4250 c:\windows\temp\wrstemp\S-1-5-20.dat
+ 2009-05-13 15:17 . 2009-05-13 15:17 4182 c:\windows\temp\wrstemp\S-1-5-19.dat
+ 2009-05-13 15:17 . 2009-05-13 15:17 3678 c:\windows\temp\wrstemp\S-1-5-18.dat
+ 2004-08-09 04:28 . 2008-12-16 12:47 351232 c:\windows\system32\winhttp.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 351232 c:\windows\system32\winhttp.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 233472 c:\windows\system32\webcheck.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2004-08-09 05:41 . 2009-02-06 16:39 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2004-08-09 05:41 . 2009-02-09 10:20 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2004-08-09 05:41 . 2009-02-09 10:20 473088 c:\windows\system32\wbem\fastprox.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 105984 c:\windows\system32\url.dll
+ 2004-08-09 04:28 . 2009-02-06 17:14 110592 c:\windows\system32\services.exe
+ 2004-08-09 04:28 . 2009-02-09 10:20 399360 c:\windows\system32\rpcss.dll
+ 2004-08-09 04:28 . 2009-05-08 23:31 405310 c:\windows\system32\perfh009.dat
- 2004-08-09 04:28 . 2009-03-16 16:26 405310 c:\windows\system32\perfh009.dat
+ 2004-08-09 04:28 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 102912 c:\windows\system32\occache.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 714752 c:\windows\system32\ntdll.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 671232 c:\windows\system32\mstime.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 193024 c:\windows\system32\msrating.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 477696 c:\windows\system32\mshtmled.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
+ 2007-08-13 22:54 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
- 2007-08-13 22:54 . 2008-12-20 23:15 459264 c:\windows\system32\msfeeds.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 161792 c:\windows\system32\msdtcuiu.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 956928 c:\windows\system32\msdtctm.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 428032 c:\windows\system32\msdtcprx.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 723456 c:\windows\system32\lsasrv.dll
+ 2004-08-09 04:28 . 2009-03-21 14:18 986112 c:\windows\system32\kernel32.dll
+ 2007-08-13 22:34 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
+ 2007-07-11 16:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
- 2007-07-11 16:27 . 2008-12-20 23:15 383488 c:\windows\system32\ieapfltr.dll
+ 2008-04-11 23:33 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
- 2008-04-11 23:33 . 2008-12-19 05:23 161792 c:\windows\system32\ieakui.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 133120 c:\windows\system32\extmgr.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 214528 c:\windows\system32\dxtrans.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
+ 2008-11-12 21:02 . 2008-11-12 21:02 170608 c:\windows\system32\drivers\ssidrv.sys
+ 2004-08-09 05:41 . 2008-04-21 10:02 215552 c:\windows\system32\dllcache\wordpad.exe
+ 2004-08-09 05:41 . 2009-02-06 16:39 227840 c:\windows\system32\dllcache\wmiprvse.exe
+ 2004-08-09 05:41 . 2009-02-09 10:20 453120 c:\windows\system32\dllcache\wmiprvsd.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 826368 c:\windows\system32\dllcache\wininet.dll
+ 2004-08-09 04:28 . 2009-03-03 00:18 826368 c:\windows\system32\dllcache\wininet.dll
+ 2004-08-09 04:28 . 2008-12-16 12:47 351232 c:\windows\system32\dllcache\winhttp.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 351232 c:\windows\system32\dllcache\winhttp.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 233472 c:\windows\system32\dllcache\webcheck.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-09 04:28 . 2009-02-06 17:14 110592 c:\windows\system32\dllcache\services.exe
+ 2004-08-09 04:28 . 2009-02-09 10:20 399360 c:\windows\system32\dllcache\rpcss.dll
+ 2004-08-09 04:28 . 2009-03-06 14:44 283648 c:\windows\system32\dllcache\pdh.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 283648 c:\windows\system32\dllcache\pdh.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 102912 c:\windows\system32\dllcache\occache.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 714752 c:\windows\system32\dllcache\ntdll.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 671232 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 193024 c:\windows\system32\dllcache\msrating.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-04-13 01:18 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2008-04-13 01:18 . 2008-12-20 23:15 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2004-08-09 05:41 . 2008-06-12 14:16 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 723456 c:\windows\system32\dllcache\lsasrv.dll
+ 2004-08-09 04:28 . 2009-03-21 14:18 986112 c:\windows\system32\dllcache\kernel32.dll
+ 2004-08-09 05:43 . 2009-02-28 04:54 636072 c:\windows\system32\dllcache\iexplore.exe
+ 2008-04-13 01:18 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-13 01:18 . 2008-12-20 23:15 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-04-13 01:18 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2008-04-11 23:33 . 2008-12-19 05:23 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2008-04-11 23:33 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-09 05:41 . 2009-02-09 10:20 473088 c:\windows\system32\dllcache\fastprox.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 133120 c:\windows\system32\dllcache\extmgr.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 616960 c:\windows\system32\dllcache\advapi32.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 616960 c:\windows\system32\dllcache\advapi32.dll
+ 2009-05-11 04:46 . 2008-11-13 22:04 511328 c:\windows\system32\capicom.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 124928 c:\windows\system32\advpack.dll
- 2004-08-09 04:28 . 2004-08-04 19:00 616960 c:\windows\system32\advapi32.dll
+ 2004-08-09 04:28 . 2009-02-09 10:20 616960 c:\windows\system32\advapi32.dll
- 2008-04-13 00:31 . 2009-04-12 19:11 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-04-13 00:31 . 2009-05-08 19:05 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-04-13 00:31 . 2009-05-08 19:05 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-04-13 00:31 . 2009-05-08 19:05 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-04-13 00:31 . 2009-05-08 19:05 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-04-13 00:31 . 2009-05-08 19:05 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2008-04-13 00:31 . 2009-05-08 19:05 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-05-08 19:11 . 2008-12-20 23:15 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-05-08 19:11 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-05-08 19:11 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-05-08 19:11 . 2008-12-20 23:15 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-05-08 19:11 . 2008-12-19 05:25 634024 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-05-08 19:11 . 2008-12-20 23:15 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-05-08 19:11 . 2008-12-19 05:23 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
- 2004-08-09 04:28 . 2008-12-20 23:15 1160192 c:\windows\system32\urlmon.dll
+ 2004-08-09 04:28 . 2008-12-20 22:43 1287680 c:\windows\system32\quartz.dll
- 2004-08-09 04:28 . 2008-05-07 05:18 1287680 c:\windows\system32\quartz.dll
+ 2004-08-09 04:28 . 2009-02-06 17:24 2180480 c:\windows\system32\ntoskrnl.exe
+ 2004-08-04 05:59 . 2009-02-06 16:49 2057728 c:\windows\system32\ntkrnlpa.exe
- 2004-08-04 05:59 . 2008-08-14 09:22 2057728 c:\windows\system32\ntkrnlpa.exe
+ 2004-08-09 04:28 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
+ 2007-08-13 22:54 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
+ 2007-02-12 20:10 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
- 2007-02-12 20:10 . 2007-04-17 09:32 2455488 c:\windows\system32\ieapfltr.dat
- 2004-08-09 04:28 . 2008-12-20 23:15 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-09 04:28 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
- 2004-08-09 04:28 . 2008-05-07 05:18 1287680 c:\windows\system32\dllcache\quartz.dll
+ 2004-08-09 04:28 . 2008-12-20 22:43 1287680 c:\windows\system32\dllcache\quartz.dll
+ 2007-02-28 09:10 . 2009-02-06 17:24 2180480 c:\windows\system32\dllcache\ntoskrnl.exe
- 2007-02-28 08:38 . 2008-08-14 09:22 2015744 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2007-02-28 08:38 . 2009-02-06 16:49 2015744 c:\windows\system32\dllcache\ntkrpamp.exe
- 2007-02-28 08:38 . 2008-08-14 09:22 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2007-02-28 08:38 . 2009-02-06 16:49 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2007-02-28 09:08 . 2008-08-14 09:58 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2007-02-28 09:08 . 2009-02-06 17:22 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2004-08-09 04:28 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
+ 2008-04-13 01:18 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
- 2008-04-13 01:18 . 2007-07-01 03:31 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2008-04-13 01:18 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2008-04-13 00:31 . 2009-05-08 19:05 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-04-13 00:31 . 2009-05-08 19:05 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
- 2008-04-13 00:31 . 2009-04-12 19:11 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-05-08 19:11 . 2008-12-20 23:15 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-05-08 19:11 . 2009-01-17 02:35 3594752 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-05-08 19:11 . 2008-12-20 23:15 6066688 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-05-08 19:11 . 2007-04-17 09:32 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2005-03-02 00:59 . 2009-02-06 17:24 2180480 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2005-03-02 00:34 . 2009-02-06 16:49 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2005-03-02 00:34 . 2008-08-14 09:22 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2005-03-02 00:34 . 2008-08-14 09:22 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2005-03-02 00:34 . 2009-02-06 16:49 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2005-03-02 00:57 . 2008-08-14 09:58 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2005-03-02 00:57 . 2009-02-06 17:22 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-04-12 19:03 . 2009-04-06 14:57 24921544 c:\windows\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 22:04 238968 ----a-w c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-02 1947928]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-06 148888]
"VTTimer"="c:\windows\system32\VTTimer.exe" [2004-10-22 53248]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2009-01-13 278264]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-02-27 1851128]
"COMODO Internet Security"="c:\program files\COMODO\Firewall\cfp.exe" [2009-02-27 1851128]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="c:\windows\system32\nwiz.exe" [2008-05-16 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"BootSkin Startup Jobs"="c:\progra~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" [2004-04-26 270336]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2009-01-12 09:22 184320 ----a-w c:\program files\AlienGUIse\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-02 13:19 11952 ----a-w c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^Alienware Dock.lnk]
backup=c:\windows\pss\Alienware Dock.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^ImpulseNow.lnk]
backup=c:\windows\pss\ImpulseNow.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
backup=c:\windows\pss\Stardock ObjectDock.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II Trial\\EMPIRES2.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\RosettaStoneLtdServices.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\Diablo\\Diablo.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.1.9806-to-3.1.1.9835-enUS-downloader.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Electronic Arts\\Need For Speed III\\nfs3.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22898:TCP"= 22898:TCP:BitComet 22898 TCP
"22898:UDP"= 22898:UDP:BitComet 22898 UDP
"16609:TCP"= 16609:TCP:BitCometLite 16609 TCP
"16609:UDP"= 16609:UDP:BitCometLite 16609 UDP
"<NO NAME>"=
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 BootScreen;BootScreen;c:\windows\\SystemRoot\System32\drivers\vidstub.sys [x]
R3 dump_wmimmc;dump_wmimmc;c:\program files\9Dragons\GameGuard\dump_wmimmc.sys [x]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408]
S0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2008-11-12 29808]
S0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2008-12-16 21144]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-05-02 325896]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-05-02 108552]
S1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2009-02-27 110992]
S1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2009-02-27 24336]
S1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2008-03-12 159896]
S1 pctmp;PC Tools Firewall Memory Protection Driver;c:\windows\system32\drivers\pctmp.sys [2008-02-21 40856]
S1 pctssipc;PC Tools Security Suite IPC Driver;c:\windows\system32\drivers\pctssipc.sys [2008-02-21 18328]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-31 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-22 55024]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-05-02 908568]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-05-02 298776]
S2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [2008-11-13 1086840]


--- Other Services/Drivers In Memory ---

*Deregistered* - 6to4
*Deregistered* - aawservice
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avg8emc
*Deregistered* - avg8wd
*Deregistered* - AvgLdx86
*Deregistered* - AvgMfx86
*Deregistered* - AvgTdiX
*Deregistered* - BANTExt
*Deregistered* - Beep
*Deregistered* - BootScreen
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - cmdAgent
*Deregistered* - cmdGuard
*Deregistered* - cmdHlp
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - hmonitor
*Deregistered* - HTTP
*Deregistered* - ImapiService
*Deregistered* - Inspect
*Deregistered* - Ip6Fw
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - mcdbus
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NVSvc
*Deregistered* - pctfw2
*Deregistered* - pctmp
*Deregistered* - pctssipc
*Deregistered* - PnkBstrA
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RpcSs
*Deregistered* - SASDIFSV
*Deregistered* - SASKUTIL
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SFilter
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssfs0bbc
*Deregistered* - sshrmd
*Deregistered* - ssidrv
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - tunmp
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - Vmodem
*Deregistered* - VolSnap
*Deregistered* - Vpctcom
*Deregistered* - Vvoice
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebrootSpySweeperService
*Deregistered* - winmgmt
*Deregistered* - WRConsumerService
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WudfPf
*Deregistered* - WudfSvc
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2009-05-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 22:57]

2009-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2081054606-3104491657-858206439-1009.job
- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-10 05:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.toggle.com/en/index.php?rvs=hompag&d=79919181
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\5lemim38.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.toadtastic.com
FF - component: c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\5lemim38.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}\components\FFAlert.dll
FF - component: c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\5lemim38.default\extensions\piclens@cooliris.com\components\piclensstub.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-13 10:23
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2081054606-3104491657-858206439-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
@SACL=
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1132)
c:\windows\system32\guard32.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\AlienGUIse\wbsrv.dll

- - - - - - - > 'lsass.exe'(1192)
c:\windows\system32\guard32.dll

- - - - - - - > 'explorer.exe'(3064)
c:\windows\system32\guard32.dll
c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
c:\windows\system32\browselc.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Stardock\Object Desktop\IconPackager\iprepair.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\COMODO\Firewall\cmdagent.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Webroot\WebrootSecurity\SpySweeper.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2009-05-13 10:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-13 15:28
ComboFix2.txt 2009-05-07 00:02
ComboFix3.txt 2009-04-06 00:21

Pre-Run: 38,690,603,008 bytes free
Post-Run: 38,742,753,280 bytes free

661 --- E O F --- 2009-05-08 19:12

#6 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:08:08 PM

Posted 13 May 2009 - 10:44 AM

Hi,

This looks OK again.

* Go to start > run and copy and paste next command in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Let me know in your next reply how things are now.

Extra note, since you are using Firefox, also do the following...

1. Please download GooredFix and save it to your Desktop.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 jaybird2000

jaybird2000
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:01:08 PM

Posted 13 May 2009 - 11:01 AM

GooredFix v1.92 by jpshortstuff
Log created at 10:59 on 13/05/2009 running Option #2 (Compaq_Owner)
Firefox version 3.0.10 (en-US)

=====Goored Deletions=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"


there it is.Computer seems back to normal no threat detected pop ups or anything

#8 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:08:08 PM

Posted 13 May 2009 - 11:13 AM

Ok,

This looks OK again as well.
Glad to hear everything is OK again. :thumbup2:

Please read my Prevention page with lots of info and tips how to prevent this in the future.
And if you want to improve speed/system performance after malware removal, take a look here.
Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.

Happy Surfing again!
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:08:08 PM

Posted 16 May 2009 - 05:17 PM

Since this issue appears resolved ... this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users