Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Gmer, dds logs


  • This topic is locked This topic is locked
16 replies to this topic

#1 jackngwen2004

jackngwen2004

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:17 AM

Posted 09 May 2011 - 10:30 AM

Referred from here: http://www.bleepingcomputer.com/forums/topic395296.html ~ OB


DDS (Ver_11-03-05.01) - NTFSx86
Run by jackngwen at 14:08:33.37 on Wed 01/03/2007
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3198.2544 [GMT -6:00]
.
AV: Symantec AntiVirus Corporate Edition *Enabled/Outdated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\ALCFDRTM.EXE
svchost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\jackngwen\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [CarboniteSetupLite] "c:\program files\carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900
mRun: [MaxMenuMgr] "c:\program files\seagate\seagatemanager\freeagent status\StxMenuMgr.exe"
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
.
============= SERVICES / DRIVERS ===============
.
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-2-4 324232]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-2-4 53896]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-4-8 185968]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-4-8 161392]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-9-26 189736]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-4-17 1706176]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110430.002\naveng.sys [2011-5-1 86136]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110430.002\navex15.sys [2011-5-1 1393144]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-4-8 83568]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys --> c:\windows\system32\drivers\nvhda32.sys [?]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-4-17 124608]
.
=============== Created Last 30 ================
.
2011-05-01 11:26:25 -------- d-sh--w- c:\documents and settings\jackngwen\IECompatCache
2011-04-30 11:07:55 -------- d-----w- c:\docume~1\jackng~1\locals~1\applic~1\Help
2011-04-26 11:02:00 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-04-26 11:01:03 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-04-26 10:55:22 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-04-26 10:31:50 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-04-24 12:35:51 -------- d-sh--w- c:\documents and settings\jackngwen\PrivacIE
2011-04-24 11:04:25 -------- d-sh--w- c:\documents and settings\jackngwen\IETldCache
2011-04-24 10:38:51 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-04-24 10:38:50 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-04-24 10:38:50 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-04-24 10:38:50 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-04-24 10:38:50 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-04-24 10:38:50 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-04-24 10:38:50 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-04-24 02:00:57 11868 ------w- c:\windows\system32\drivers\mdmxsdk.sys
2011-04-24 02:00:44 685056 ------w- c:\windows\system32\drivers\hsfcxts2.sys
2011-04-24 02:00:44 1041536 ------w- c:\windows\system32\drivers\hsfdpsp2.sys
2011-04-24 02:00:43 220032 ------w- c:\windows\system32\drivers\hsfbs2s2.sys
2011-04-24 02:00:19 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2011-04-24 01:49:27 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2011-04-24 01:49:27 140288 ----a-w- c:\windows\system32\Comdlg32.ocx
2011-04-24 01:49:27 118784 ----a-w- c:\windows\system32\vbalNCSM6.dll
2011-04-24 01:49:27 1064456 ----a-w- c:\windows\system32\Mscomctl.ocx
2011-04-24 01:49:25 101888 ----a-w- c:\windows\system32\Vb6stkit.dll
2011-04-24 01:49:24 70088 ----a-w- c:\windows\system32\Project2-1.ocx
2011-04-24 01:14:20 626960 ----a-r- c:\windows\system32\hpvaut32.dll
2011-04-24 01:14:20 487424 ----a-r- c:\windows\system32\hpvcp70.dll
2011-04-24 01:14:20 44544 ----a-r- c:\windows\system32\MSXML4a.dll
2011-04-24 01:14:20 344064 ----a-w- c:\windows\system32\hpvcr70.dll
2011-04-24 01:13:30 45056 ----a-r- c:\docume~1\jackng~1\applic~1\microsoft\installer\{457791c5-d702-4143-a7b2-2744be9573f2}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2011-04-24 01:10:26 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-04-24 01:10:00 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2011-04-24 01:10:00 65536 ----a-w- c:\windows\system32\HPZipm12.exe
2011-04-24 01:10:00 61440 ----a-w- c:\windows\system32\HPZinw12.exe
2011-04-24 01:10:00 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2011-04-24 01:09:59 306688 ----a-w- c:\windows\IsUninst.exe
2011-04-24 01:09:59 278584 ----a-w- c:\windows\system32\HPZidr12.dll
2011-04-24 01:09:59 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2011-04-23 23:09:03 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-04-23 23:09:03 272128 ------w- c:\windows\system32\drivers\bthport.sys
2011-04-23 23:08:48 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2011-04-23 23:07:53 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-04-23 23:07:53 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-04-23 23:06:14 357888 -c----w- c:\windows\system32\dllcache\srv.sys
2011-04-23 23:00:08 455936 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-04-23 22:59:34 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2011-04-23 22:58:03 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2011-04-23 22:58:03 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2011-04-23 22:58:03 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2011-04-23 22:58:03 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2011-04-23 22:58:03 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2011-04-23 22:58:03 110592 -c----w- c:\windows\system32\dllcache\services.exe
2011-04-23 22:58:02 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2011-04-23 22:58:02 718336 -c----w- c:\windows\system32\dllcache\ntdll.dll
2011-04-23 22:58:02 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2011-04-23 22:58:02 2148864 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-04-23 22:58:01 2192768 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-04-23 22:58:01 2027008 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-04-23 22:50:55 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2011-04-23 22:43:34 -------- d-----w- c:\docume~1\jackng~1\applic~1\Malwarebytes
2011-04-23 22:43:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-23 22:43:28 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2011-04-23 22:43:20 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-23 22:31:40 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2011-04-23 22:29:42 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Seagate
2011-04-23 22:28:21 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-04-23 22:28:21 218112 -c----w- c:\windows\system32\dllcache\wordpad.exe
2011-04-23 22:27:34 -------- d-----w- c:\docume~1\jackng~1\locals~1\applic~1\Downloaded Installations
2011-04-23 22:26:59 -------- d-----w- c:\program files\MSXML 6.0
2011-04-23 21:45:46 -------- d-----w- c:\docume~1\jackng~1\locals~1\applic~1\Symantec
2011-04-23 21:45:00 91856 ----a-w- c:\windows\system32\S32EVNT1.DLL
2011-04-23 21:45:00 123200 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-04-23 21:41:43 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\Symantec
2011-04-23 11:41:36 -------- d-----w- c:\program files\EVGA Precision
2011-04-16 19:52:19 -------- d-----w- c:\docume~1\jackng~1\locals~1\applic~1\Adobe
2011-04-16 19:42:39 73728 ----a-w- c:\windows\ALCFDRTM.EXE
2011-04-16 19:41:01 1957888 ----a-w- c:\windows\system32\xRaidSetup.exe
2011-04-16 19:41:01 143360 ----a-w- c:\windows\system32\xRaidAPI.dll
2011-04-16 19:39:40 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2011-04-16 19:39:31 520192 ----a-w- c:\windows\RtlExUpd.dll
2011-04-16 19:39:31 315392 ----a-w- c:\windows\HideWin.exe
2011-04-16 19:21:58 98304 -c--a-w- c:\windows\system32\dllcache\msir3jp.dll
2011-04-16 19:19:20 -------- d-sh--w- c:\documents and settings\all users.windows\DRM
2011-04-16 19:17:58 73472 ----a-w- c:\windows\system32\drivers\sr.sys
2011-04-16 19:16:46 33792 ----a-w- c:\program files\messenger\custsat.dll
2011-04-16 16:55:06 -------- d-----w- C:\$WIN_NT$.~BT
2011-04-16 16:55:02 -------- d-----w- c:\windows\setup.pss
2011-04-16 16:08:38 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-04-16 16:08:37 -------- d-----w- c:\windows\system32\wbem\Repository
2011-04-16 13:46:15 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2011-04-16 13:45:19 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-04-16 13:44:54 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-04-16 13:44:30 6400 ----a-w- c:\windows\system32\drivers\enum1394.sys
2011-04-16 13:43:47 74240 ----a-w- c:\windows\system32\usbui.dll
2011-04-16 13:39:59 -------- d-----r- c:\documents and settings\all users.windows\Documents
2011-04-16 13:38:48 14573 ----a-r- c:\windows\SET29.tmp
2011-04-16 13:38:17 13753 ----a-r- c:\windows\SET8.tmp
2011-04-16 13:38:15 1086058 ----a-r- c:\windows\SET4.tmp
2011-04-16 13:38:14 1056254 ----a-r- c:\windows\SET3.tmp
2011-03-28 14:42:00 -------- d-----w- c:\program files\Microsoft Security Client
2011-03-25 16:46:08 -------- d-----w- c:\program files\AVAST Software
2011-03-15 20:13:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-15 18:52:24 -------- d-----w- c:\windows\system32\NtmsData
2011-03-05 21:03:14 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-03-05 18:36:12 -------- d-----w- c:\program files\Carbonite
2011-03-05 18:35:49 -------- d-----w- c:\program files\Seagate
2011-03-05 18:35:35 -------- d-----w- c:\program files\common files\muvee Technologies
2011-02-25 21:08:41 -------- d-----w- C:\7b02fe4d2b4a8726109cc521
2011-02-25 21:06:18 -------- d-----w- C:\8302b15c3eefa9ec63738dab
2011-02-24 21:46:47 -------- d-----w- c:\program files\Symantec
2011-02-24 21:46:37 -------- d-----w- c:\program files\Symantec AntiVirus
2011-02-24 21:46:37 -------- d-----w- c:\program files\common files\Symantec Shared
2011-02-24 18:23:32 -------- d-----w- c:\program files\common files\DivX Shared
2011-02-24 18:05:05 -------- d-----w- c:\program files\DivX
2011-02-24 15:03:21 -------- d-----w- c:\program files\eGames
2011-02-20 20:44:26 -------- d-----w- c:\program files\common files\Rockwell
2011-02-20 20:36:06 -------- d-----w- c:\program files\Rockwell Software
2011-02-12 22:02:27 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2011-02-09 13:53:52 270848 -c----w- c:\windows\system32\dllcache\sbe.dll
2011-02-09 13:53:52 186880 -c----w- c:\windows\system32\dllcache\encdec.dll
2011-02-08 13:33:55 978944 -c----w- c:\windows\system32\dllcache\mfc42.dll
2011-02-08 13:33:55 974848 -c----w- c:\windows\system32\dllcache\mfc42u.dll
2011-02-02 07:58:35 2067456 -c----w- c:\windows\system32\dllcache\lhmstscx.dll
2011-01-27 11:57:06 677888 -c----w- c:\windows\system32\dllcache\lhmstsc.exe
2011-01-21 14:44:37 439296 -c----w- c:\windows\system32\dllcache\shimgvw.dll
2011-01-18 22:07:36 -------- d-----w- c:\program files\2K Games
2010-12-30 12:08:42 -------- d-----w- C:\UnrealTournament
2010-11-18 18:12:44 81920 -c----w- c:\windows\system32\dllcache\isign32.dll
2010-11-09 14:52:35 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2010-11-09 14:52:35 249856 -c----w- c:\windows\system32\dllcache\odbc32.dll
2010-11-09 14:52:35 200704 -c----w- c:\windows\system32\dllcache\msadox.dll
2010-11-09 14:52:35 180224 -c----w- c:\windows\system32\dllcache\msadomd.dll
2010-11-09 14:52:35 143360 -c----w- c:\windows\system32\dllcache\msadco.dll
2010-11-09 14:52:35 102400 -c----w- c:\windows\system32\dllcache\msjro.dll
2010-10-04 22:02:56 105152 ----a-w- c:\program files\common files\microsoft shared\smart tag\IETAG.DLL
2010-10-04 21:59:42 9811792 ----a-w- c:\program files\common files\microsoft shared\office10\MSO.DLL
2010-09-24 10:30:23 -------- d-----w- C:\MicroProse
2010-08-27 05:57:43 99840 -c----w- c:\windows\system32\dllcache\srvsvc.dll
2010-08-17 13:17:06 58880 -c----w- c:\windows\system32\dllcache\spoolsv.exe
2010-08-10 00:01:40 406016 ----a-w- c:\program files\common files\microsoft shared\office10\USP10.DLL
2010-07-27 01:28:04 744128 ----a-w- c:\program files\common files\system\mapi\1033\OUTEX.DLL
2010-07-27 01:28:00 535312 ----a-w- c:\program files\common files\system\mapi\1033\MSPST32.DLL
2010-07-27 01:27:58 857944 ----a-w- c:\program files\common files\system\mapi\1033\MSMAPI32.DLL
2010-07-27 01:27:56 539336 ----a-w- c:\program files\common files\system\mapi\1033\EMSMDB32.DLL
2010-07-27 01:27:54 199368 ----a-w- c:\program files\common files\system\mapi\1033\EMSABP32.DLL
2010-07-27 01:27:50 113352 ----a-w- c:\program files\common files\system\mapi\1033\EMABLT32.DLL
2010-07-27 01:27:48 133832 ----a-w- c:\program files\common files\system\mapi\1033\CONTAB32.DLL
2010-07-16 12:05:55 1288192 -c----w- c:\windows\system32\dllcache\ole32.dll
2010-06-18 17:45:17 293376 -c----w- c:\windows\system32\dllcache\winsrv.dll
2010-06-13 21:08:18 -------- d-----w- c:\windows\ie8updates
2010-06-13 21:05:10 -------- dc-h--w- c:\windows\ie8
2010-06-13 21:04:37 -------- d-----w- c:\program files\Microsoft
2010-06-13 21:04:31 -------- d-----w- c:\program files\MSN Toolbar
2010-06-13 20:57:52 -------- d-----w- c:\program files\Bing Bar Installer
2010-05-24 19:49:34 39624 ----a-w- c:\program files\common files\system\mapi\1033\DUMPSTER.DLL
2010-05-02 05:22:50 1857920 -c----w- c:\windows\system32\dllcache\win32k.sys
2010-04-16 15:36:56 406016 -c----w- c:\windows\system32\dllcache\usp10.dll
2010-03-05 14:37:40 65536 -c----w- c:\windows\system32\dllcache\asycfilt.dll
2010-02-12 04:33:11 100864 -c----w- c:\windows\system32\dllcache\6to4svc.dll
2010-02-05 18:27:45 1291776 -c----w- c:\windows\system32\dllcache\quartz.dll
2010-01-29 15:01:31 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-01-29 15:01:30 692736 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-01-13 14:01:25 86016 -c----w- c:\windows\system32\dllcache\cabview.dll
2010-01-12 00:07:58 2594632 ----a-w- c:\program files\common files\microsoft shared\vba\vba6\VBE6.DLL
2010-01-10 15:36:17 -------- d-----w- c:\program files\iWin.com
2010-01-08 19:29:01 -------- d-----w- c:\program files\Yahoo! Games
2009-12-24 06:59:40 177664 -c----w- c:\windows\system32\dllcache\wintrust.dll
2009-12-16 18:43:27 343040 -c----w- c:\windows\system32\dllcache\mspaint.exe
2009-12-14 07:08:23 33280 -c----w- c:\windows\system32\dllcache\csrsrv.dll
2009-12-08 09:23:28 474112 -c----w- c:\windows\system32\dllcache\shlwapi.dll
2009-11-29 21:09:52 -------- d-----w- c:\windows\system32\XPSViewer
2009-11-29 21:09:14 -------- d-----w- C:\917d5911a7e35e451ac5
2009-11-27 17:11:44 17920 -c----w- c:\windows\system32\dllcache\msyuv.dll
2009-11-27 16:37:27 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll
2009-11-27 16:07:34 84992 -c----w- c:\windows\system32\dllcache\avifil32.dll
2009-11-27 16:07:34 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll
2009-11-27 16:07:34 11264 -c----w- c:\windows\system32\dllcache\msrle32.dll
2009-11-05 20:18:58 119648 ----a-w- c:\program files\common files\microsoft shared\textconv\msconv97.dll
2009-10-26 12:07:10 -------- d-----w- c:\program files\Docs
2009-10-26 12:06:56 -------- d-----w- c:\program files\xatrix
2009-10-26 12:06:40 -------- d-----w- c:\program files\rogue
2009-10-26 12:06:39 -------- d-----w- c:\program files\ctf
2009-10-26 12:06:09 -------- d-----w- c:\program files\baseq2
2009-10-21 05:38:36 75776 -c----w- c:\windows\system32\dllcache\strmfilt.dll
2009-10-21 05:38:36 25088 -c----w- c:\windows\system32\dllcache\httpapi.dll
2009-10-20 16:20:16 265728 -c----w- c:\windows\system32\dllcache\http.sys
2009-10-13 10:30:16 270336 -c----w- c:\windows\system32\dllcache\oakley.dll
2009-10-12 13:38:19 149504 -c----w- c:\windows\system32\dllcache\rastls.dll
2009-10-12 13:38:18 79872 -c----w- c:\windows\system32\dllcache\raschap.dll
2009-09-25 17:42:22 -------- d-----w- c:\program files\SelectRebates
2009-09-11 14:18:39 136192 -c----w- c:\windows\system32\dllcache\msv1_0.dll
2009-09-05 13:46:23 -------- d-----w- c:\windows\Cache
2009-09-05 13:46:23 -------- d-----w- c:\program files\Coupons
2009-09-04 21:03:36 58880 -c----w- c:\windows\system32\dllcache\msasn1.dll
2009-09-01 11:37:19 -------- d-----w- C:\Ring
2009-08-25 09:17:27 354816 -c----w- c:\windows\system32\dllcache\winhttp.dll
2009-08-19 22:07:18 1372672 ----a-w- c:\windows\system32\msxml6.dll
2009-08-18 16:34:24 602528 ----a-w- c:\program files\common files\microsoft shared\windows live\WLIDRES.DLL
2009-08-18 16:32:12 403840 ----a-w- c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
2009-08-18 16:30:38 97176 ----a-w- c:\program files\common files\microsoft shared\windows live\LogicalDevice.dll
2009-08-18 16:30:38 807832 ----a-w- c:\program files\common files\microsoft shared\windows live\msidcrl40.dll
2009-08-18 16:30:38 233352 ----a-w- c:\program files\common files\microsoft shared\windows live\HWDeviceLogin.dll
2009-08-18 16:29:22 344448 ----a-w- c:\program files\common files\microsoft shared\windows live\SIGNINOPTIONS.EXE
2009-08-18 16:29:22 183152 ----a-w- c:\program files\common files\microsoft shared\windows live\WLIDSVCM.EXE
2009-08-18 16:29:22 1529728 ----a-w- c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE
2009-08-18 16:24:10 134144 ----a-w- c:\program files\common files\microsoft shared\windows live\SQMAPI.DLL
2009-08-07 00:24:18 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2009-08-07 00:24:12 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2009-08-07 00:24:06 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2009-08-07 00:24:00 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2009-08-05 09:01:48 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-27 23:17:41 135168 -c----w- c:\windows\system32\dllcache\shsvcs.dll
2009-07-26 15:53:30 -------- d-----w- c:\windows\Logs
2009-07-23 11:35:51 -------- d-----w- c:\windows\system32\xlive
2009-07-21 05:05:40 1348432 ----a-w- c:\windows\system32\msxml4.dll
2009-07-20 08:13:30 7255872 ----a-w- c:\program files\common files\microsoft shared\web components\10\OWC10.DLL
2009-07-17 16:22:18 1435648 -c----w- c:\windows\system32\dllcache\query.dll
2009-07-12 18:11:20 670016 ----a-w- c:\program files\common files\microsoft shared\vc\msdia90.dll
2009-07-12 02:37:20 641536 ----a-w- c:\program files\common files\microsoft shared\vc\msdia80.dll
2009-06-25 08:25:26 54272 -c----w- c:\windows\system32\dllcache\wdigest.dll
2009-06-25 08:25:26 301568 -c----w- c:\windows\system32\dllcache\kerberos.dll
2009-06-24 11:18:41 92928 -c----w- c:\windows\system32\dllcache\ksecdd.sys
2009-06-12 12:31:40 80896 -c----w- c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 12:31:39 76288 -c----w- c:\windows\system32\dllcache\telnet.exe
2009-06-10 06:14:49 132096 -c----w- c:\windows\system32\dllcache\wkssvc.dll
2009-05-07 15:32:35 345600 -c----w- c:\windows\system32\dllcache\localspl.dll
2009-05-01 22:12:21 -------- d-----w- c:\program files\Linksys
2009-04-20 17:17:26 45568 -c----w- c:\windows\system32\dllcache\dnsrslvr.dll
2009-04-15 14:51:25 590848 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2009-03-21 14:06:58 989696 -c----w- c:\windows\system32\dllcache\kernel32.dll
2009-03-11 03:18:14 934792 -c----w- c:\windows\system32\dllcache\WgaTray.exe
2009-03-11 03:18:00 239496 -c----w- c:\windows\system32\dllcache\wgaLogon.dll
2009-03-08 19:22:46 1241088 ------w- c:\windows\system32\ieframe.dll.mui
2009-03-08 19:22:30 49152 ------w- c:\windows\system32\msrating.dll.mui
2009-03-08 19:22:18 2560 ------w- c:\windows\system32\mshta.exe.mui
2009-03-08 19:21:06 4096 ------w- c:\windows\system32\ie4uinit.exe.mui
2009-03-08 19:21:06 10240 ------w- c:\windows\system32\advpack.dll.mui
2009-03-08 19:20:54 81920 ------w- c:\windows\system32\iedkcs32.dll.mui
2009-03-08 09:35:32 743424 ----a-w- c:\program files\internet explorer\iedvtool.dll
2009-03-08 09:35:12 233984 ----a-w- c:\program files\internet explorer\jsprofilerui.dll
2009-03-08 09:35:04 41984 ----a-w- c:\program files\internet explorer\iecompat.dll
2009-03-08 09:35:04 144384 ----a-w- c:\program files\internet explorer\ExtExport.exe
2009-03-08 09:35:04 118272 ----a-w- c:\program files\internet explorer\JSProfilerCore.dll
2009-03-08 09:35:02 521216 ----a-w- c:\program files\internet explorer\jsdbgui.dll
2009-03-08 09:35:02 121344 ----a-w- c:\program files\internet explorer\jsdebuggeride.dll
2009-03-08 09:33:18 12800 ----a-w- c:\program files\internet explorer\xpshims.dll
2009-02-08 00:02:58 2069376 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-03 19:59:07 56832 -c----w- c:\windows\system32\dllcache\secur32.dll
2009-01-07 23:20:54 134144 -c----w- c:\windows\system32\dllcache\sqmapi.dll
2009-01-07 23:20:54 134144 ----a-w- c:\program files\internet explorer\sqmapi.dll
2009-01-07 23:20:38 24576 ----a-w- c:\windows\system32\nlsdl.dll
2009-01-07 23:20:36 26112 ----a-w- c:\windows\system32\idndl.dll
2009-01-07 23:20:36 23552 ----a-w- c:\windows\system32\normaliz.dll
2009-01-07 23:20:18 355832 ----a-w- c:\program files\internet explorer\pdm.dll
2009-01-07 23:20:18 265720 ----a-w- c:\windows\system32\msdbg2.dll
2008-12-25 02:22:00 -------- d-----w- c:\program files\Kakuro Mania! 10,000
2008-12-25 02:10:45 -------- d-----w- c:\program files\4500 Slots Games
2008-12-25 02:09:59 -------- d-----w- c:\program files\1001 Minigolf Challenge
2008-12-25 01:56:50 -------- d-----w- c:\program files\Selectsoft
2008-12-25 01:54:06 -------- d-----w- c:\program files\OXXOGames
2008-12-13 01:31:29 -------- d--h--w- C:\C_DILLA
2008-12-08 13:23:16 -------- d-----w- C:\New Folder
2008-12-08 13:05:56 -------- d-----w- c:\program files\Microsoft Games
2008-12-08 13:03:13 -------- d-----w- c:\program files\directx
2008-12-05 06:54:55 149504 -c----w- c:\windows\system32\dllcache\schannel.dll
2008-10-23 12:36:14 286720 -c----w- c:\windows\system32\dllcache\gdi32.dll
2008-09-16 15:25:47 -------- d-----w- c:\program files\Microsoft Research
2008-09-10 12:10:06 -------- d-----w- c:\windows\system32\scripting
2008-09-10 12:10:05 -------- d-----w- c:\windows\l2schemas
2008-09-10 12:10:03 -------- d-----w- c:\windows\system32\en
2008-09-10 12:10:01 -------- d-----w- c:\windows\system32\bits
2008-09-10 11:58:59 -------- d-----w- c:\windows\ServicePackFiles
2008-07-30 12:05:33 -------- d-----w- c:\program files\Windows Media Connect 2
2008-07-30 12:04:33 -------- d-----w- c:\windows\system32\LogFiles
2008-07-25 17:16:58 158720 ----a-w- c:\program files\internet explorer\mui\0409\mscorier.dll
2008-07-07 20:26:58 253952 -c----w- c:\windows\system32\dllcache\es.dll
2008-06-24 16:43:16 74240 -c----w- c:\windows\system32\dllcache\mscms.dll
2008-06-20 17:46:57 245248 -c----w- c:\windows\system32\dllcache\mswsock.dll
2008-06-20 17:46:57 149504 -c----w- c:\windows\system32\dllcache\dnsapi.dll
2008-06-20 11:51:12 361600 -c----w- c:\windows\system32\dllcache\tcpip.sys
2008-06-20 11:40:08 138496 -c----w- c:\windows\system32\dllcache\afd.sys
2008-06-20 11:08:27 226880 -c----w- c:\windows\system32\dllcache\tcpip6.sys
2008-06-17 19:02:19 8462336 -c----w- c:\windows\system32\dllcache\shell32.dll
2008-06-12 14:23:32 956928 -c----w- c:\windows\system32\dllcache\msdtctm.dll
2008-06-12 14:23:32 91648 -c----w- c:\windows\system32\dllcache\mtxoci.dll
2008-06-12 14:23:32 66560 -c----w- c:\windows\system32\dllcache\mtxclu.dll
2008-06-12 14:23:32 58880 -c----w- c:\windows\system32\dllcache\msdtclog.dll
2008-06-12 14:23:32 428032 -c----w- c:\windows\system32\dllcache\msdtcprx.dll
2008-06-12 14:23:32 161792 -c----w- c:\windows\system32\dllcache\msdtcuiu.dll
2008-05-21 20:26:54 -------- d-----w- c:\windows\system32\appmgmt
2008-05-09 10:53:40 90112 -c----w- c:\windows\system32\dllcache\wshext.dll
2008-05-09 10:53:40 172032 -c----w- c:\windows\system32\dllcache\scrrun.dll
2008-05-09 10:53:39 180224 -c----w- c:\windows\system32\dllcache\scrobj.dll
2008-05-08 11:24:44 155648 -c----w- c:\windows\system32\dllcache\wscript.exe
2008-05-07 09:07:23 135168 -c----w- c:\windows\system32\dllcache\cscript.exe
2008-05-04 10:55:45 -------- d-----w- C:\Drivers
2008-05-04 10:55:38 225280 ----a-w- c:\program files\common files\installshield\iscript\IScript.dll
2008-05-04 10:55:37 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2008-05-04 10:55:37 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2008-05-04 10:55:37 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2008-04-20 19:45:55 47616 ----a-w- c:\program files\windows media player\msoobci.dll
2008-04-20 19:45:55 1669120 ----a-w- c:\program files\windows media player\wmsetsdk.exe
2008-04-20 19:45:31 -------- d-----w- c:\windows\RegisteredPackages
2008-04-20 19:20:22 -------- d-----w- c:\program files\Nero
2008-04-20 19:16:23 60048 ----a-w- c:\program files\common files\system\ole db\msdatl.dll
2008-04-20 19:16:23 -------- d-----w- c:\program files\Sierra On-Line
2008-04-20 19:16:22 62736 ----a-w- c:\program files\common files\system\ole db\MSDATL2.DLL
2008-04-20 19:16:17 582144 ----a-w- c:\program files\common files\microsoft shared\dao\dao350.dll
2008-04-20 19:12:53 -------- d-----w- C:\Sierra
2008-04-20 18:35:55 -------- d-----w- c:\program files\Webroot
2008-04-20 18:35:55 -------- d-----w- c:\program files\common files\Webroot Shared
2008-04-20 18:29:21 -------- d-----w- c:\program files\common files\Jasc Software Inc
2008-04-20 18:28:56 -------- d-----w- c:\program files\Jasc Software Inc
2008-04-20 18:22:41 -------- d-----w- c:\program files\Microsoft ActiveSync
2008-04-20 18:18:25 -------- d--h--w- c:\windows\ShellNew
2008-04-19 00:49:28 -------- d-----w- c:\windows\network diagnostic
2008-04-14 00:11:57 397312 ------w- c:\windows\system32\mmcex.dll
2008-04-14 00:09:55 6144 ------w- c:\windows\system32\kbdpash.dll
2008-04-14 00:09:55 6144 ------w- c:\windows\system32\kbdnepr.dll
2008-04-14 00:09:55 6144 ------w- c:\windows\system32\kbdiultn.dll
2008-04-14 00:09:55 6144 ------w- c:\windows\system32\kbdbhc.dll
2008-04-13 18:56:49 30592 ------w- c:\windows\system32\drivers\rndismpx.sys
2008-04-13 18:56:49 12800 ------w- c:\windows\system32\drivers\usb8023x.sys
2008-04-13 18:51:34 101120 ------w- c:\windows\system32\drivers\bthpan.sys
2008-04-13 18:46:33 37888 ------w- c:\windows\system32\drivers\bthmodem.sys
2008-04-13 18:46:33 17024 ------w- c:\windows\system32\drivers\bthenum.sys
2008-04-13 18:46:32 59136 ------w- c:\windows\system32\drivers\rfcomm.sys
2008-04-13 18:46:31 36480 ------w- c:\windows\system32\drivers\bthprint.sys
2008-04-13 18:46:30 25600 ------w- c:\windows\system32\drivers\hidbth.sys
2008-04-13 18:46:29 18944 ------w- c:\windows\system32\drivers\bthusb.sys
2008-04-13 18:46:20 121984 ------w- c:\windows\system32\drivers\usbvideo.sys
2008-04-13 18:45:34 46592 ------w- c:\windows\system32\drivers\irbus.sys
2008-04-13 18:45:26 19200 ------w- c:\windows\system32\drivers\hidir.sys
2008-04-13 18:43:55 14208 ------w- c:\windows\system32\drivers\wacompen.sys
2008-04-13 18:43:55 12672 ------w- c:\windows\system32\drivers\mutohpen.sys
2008-04-13 18:43:32 9728 ------w- c:\windows\system32\comsdupd.exe
2008-04-13 18:40:48 10240 ------w- c:\windows\system32\drivers\sffp_mmc.sys
2008-04-13 18:36:40 46464 ------w- c:\windows\system32\drivers\gagp30kx.sys
2008-04-13 18:36:40 44672 ------w- c:\windows\system32\drivers\uagp35.sys
2008-04-13 18:36:40 42240 ------w- c:\windows\system32\drivers\viaagp.sys
2008-04-13 18:36:39 44928 ------w- c:\windows\system32\drivers\agpcpq.sys
2008-04-13 18:36:39 43008 ------w- c:\windows\system32\drivers\amdagp.sys
2008-04-13 18:36:39 40960 ------w- c:\windows\system32\drivers\sisagp.sys
2008-04-13 18:36:38 42752 ------w- c:\windows\system32\drivers\alim1541.sys
2008-04-13 18:36:38 42368 ------w- c:\windows\system32\drivers\agp440.sys
2008-04-13 18:36:34 5888 ------w- c:\windows\system32\drivers\smbali.sys
2008-04-13 18:14:58 76800 ------w- c:\windows\system32\msshavmsg.dll
2008-04-13 17:27:18 79872 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2008-04-11 23:40:57 -------- d-----w- C:\5b84fc4cf29a418c2610cf81
2008-04-10 00:51:18 -------- d-----w- c:\program files\MSXML 4.0
2008-04-09 17:37:53 -------- d-----w- c:\windows\system32\PreInstall
2008-01-14 12:52:00 81920 ----a-w- c:\windows\system32\frapsvid.dll
2008-01-03 22:26:00 4274816 -c--a-w- c:\windows\system32\dllcache\nv4_disp.dll
2008-01-03 22:26:00 4274816 ----a-w- c:\windows\system32\nv4_disp.dll
2008-01-03 22:26:00 1897408 -c--a-w- c:\windows\system32\dllcache\nv4_mini.sys
2008-01-03 22:26:00 1897408 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2007-08-13 23:54:10 33792 ----a-w- c:\program files\internet explorer\custsat.dll
2007-08-13 23:54:10 247808 ----a-w- c:\program files\internet explorer\ieproxy.dll
2007-03-29 10:17:09 -------- d-----w- c:\windows\system32\SoftwareDistribution
2007-03-29 08:08:12 -------- d-----w- c:\program files\common files\HP
2007-03-29 08:06:07 -------- d-----w- c:\program files\common files\Hewlett-Packard
2007-03-29 08:05:24 -------- d-----w- c:\windows\system32\URTTemp
2007-03-29 08:01:06 -------- d-----w- c:\program files\HP
2007-03-29 07:14:00 -------- d-----w- c:\program files\F-Secure PC Protection
2007-03-29 06:36:29 -------- d-----w- c:\program files\DISHMail
2007-03-23 03:00:52 -------- d-----w- c:\program files\Lavasoft
2007-03-23 03:00:17 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2007-03-23 02:32:24 -------- d-----w- c:\windows\system32\Futuremark
2007-03-23 02:31:55 -------- d-----w- c:\program files\Futuremark
2007-03-22 06:08:47 -------- d-----w- C:\NVIDIA
2007-03-22 05:06:57 -------- d-----w- c:\program files\RivaTuner v2.08
2007-03-21 16:31:34 -------- d-sh--w- c:\windows\ftpcache
2007-03-21 16:13:25 -------- d-----w- c:\windows\pss
2007-03-21 15:54:50 -------- d-----w- C:\Fraps
2007-03-21 15:54:07 -------- d-----w- c:\windows\SxsCaPendDel
2007-03-21 15:50:54 729088 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iKernel.dll
2007-03-21 15:50:54 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\ctor.dll
2007-03-21 15:50:54 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
2007-03-21 15:50:54 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iscript.dll
2007-03-21 15:50:54 192512 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iuser.dll
2007-03-21 15:50:48 311428 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\setup.dll
2007-03-21 15:50:48 188548 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iGdi.dll
2007-03-10 09:51:57 -------- d-----w- c:\windows\system32\ageia
2007-03-08 14:06:41 -------- d-----w- c:\program files\U-ABIT
2007-03-08 14:01:47 -------- d-----w- c:\windows\system32\Lang
2007-03-08 14:00:50 -------- d-----w- C:\RaidTool
2007-03-08 14:00:48 -------- d-----w- c:\windows\RaidTool
2007-03-08 14:00:46 753664 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iKernel.dll
2007-03-08 14:00:46 69714 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\ctor.dll
2007-03-08 14:00:46 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\DotNetInstaller.exe
2007-03-08 14:00:46 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iscript.dll
2007-03-08 14:00:46 200836 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iGdi.dll
2007-03-08 14:00:46 184320 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iuser.dll
2007-03-08 14:00:45 331908 ----a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\setup.dll
2007-03-08 14:00:26 -------- d-----w- c:\windows\OPTIONS
2007-03-08 14:00:04 -------- d-----w- c:\windows\system32\RTCOM
2007-03-08 13:58:15 -------- d-----w- c:\windows\system32\ReinstallBackups
2007-03-08 13:58:10 -------- d-----w- C:\Intel
.
==================== Find3M ====================
.
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41:59 385024 ----a-w- c:\windows\system32\html.iec
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 17:26:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-09 15:15:09 718336 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30:22 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:42:26 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07:07 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52:35 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-16 12:05:55 1288192 ----a-w- c:\windows\system32\ole32.dll
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-18 17:45:17 293376 ----a-w- c:\windows\system32\winsrv.dll
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-15 16:17:24 143422 ----a-w- c:\windows\system32\l3codecx.ax
2010-06-14 14:31:20 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-02 09:55:30 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-06-02 09:55:30 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-06-02 09:55:30 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-05-26 16:41:02 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-05-26 16:41:02 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-05-26 16:41:02 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-05-26 16:41:02 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-05-26 16:41:02 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-04-16 15:36:56 406016 ----a-w- c:\windows\system32\usp10.dll
2010-04-05 16:54:04 384512 ----a-w- c:\windows\system32\mp4sdmod.dll
2010-03-30 05:52:26 262416 ----a-w- c:\windows\system32\mpg4ds32.ax
2010-03-05 14:37:40 65536 ------w- c:\windows\system32\asycfilt.dll
2010-02-12 04:33:11 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-05 18:27:45 1291776 ----a-w- c:\windows\system32\quartz.dll
2010-02-04 15:01:14 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-02-04 15:01:14 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-02-04 15:01:14 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-02-04 15:01:14 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-01-29 14:43:39 307260 ----a-w- c:\windows\system32\l3codeca.acm
2010-01-13 14:01:25 86016 ----a-w- c:\windows\system32\cabview.dll
2009-12-24 06:59:40 177664 ----a-w- c:\windows\system32\wintrust.dll
2009-12-16 18:43:27 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-11-27 17:11:44 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07:35 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07:35 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07:34 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07:34 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07:34 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-21 15:51:04 471552 ----a-w- c:\windows\apppatch\aclayers.dll
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-15 16:28:26 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-10-13 10:30:16 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 22:44:40 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 22:44:40 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-09-04 22:44:40 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-09-04 22:29:34 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-09-04 22:29:34 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-09-04 22:29:32 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-09-04 22:29:32 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-09-04 22:29:30 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 14:32:11 282654 ----a-w- c:\windows\system32\msaud32.acm
2009-08-26 08:16:37 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 09:17:27 354816 ----a-w- c:\windows\system32\winhttp.dll
2009-08-07 00:24:10 217816 ----a-w- c:\windows\system32\wuaucpl.cpl
2009-08-05 09:01:48 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55:28 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 16:22:18 1435648 ----a-w- c:\windows\system32\query.dll
2009-07-12 17:21:50 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-25 18:36:08 95744 ----a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36:08 661504 ----a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36:08 517120 ----a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36:08 48640 ----a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36:08 471552 ----a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36:08 47104 ----a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36:08 225280 ----a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36:08 186880 ----a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36:08 177152 ----a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36:08 16896 ----a-w- c:\windows\system32\mqise.dll
.
============= FINISH: 14:10:23.01 ===============
Here are the logs you requested. These are for the Graphics Card won't start Code 10 problem for Jackngwen 2004.

Attached Files


Edited by Orange Blossom, 09 May 2011 - 10:34 AM.


BC AdBot (Login to Remove)

 


#2 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:17 AM

Posted 20 May 2011 - 07:18 PM

Hi,

Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.
  • Please subscribe to this topic, if you haven't already. Click the Watch This Topic button at the top on the right.

  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

  • Please reply to this post so I know you are there.
The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.

Once I receive a reply then I will return with your first instructions.

Thanks :thumbup2:
Posted Image
m0le is a proud member of UNITE

#3 jackngwen2004

jackngwen2004
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:17 AM

Posted 21 May 2011 - 06:01 AM

Hello m0le, Thank you for your answer, I am looking forward to getting this bleepingcomputer running correctly. I will check this content daily and follow your advice. Thanks again for your help. JP

#4 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:17 AM

Posted 21 May 2011 - 06:07 AM

I see from the last topic that you ran Combofix on the machine. Can you please uninstall it if you haven't already (instructions for correct uninstalling next)

Uninstall ComboFix
  • Disable any realtime antivirus or antispyware programs.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
    (For Vista/Windows 7 please click Start -> All Programs -> Accessories -> Run)
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between "Combofix" and "/")
  • Please follow the prompts to uninstall Combofix.
  • You will then receive a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything associated with it.


and then download and run it as shown below.

Please download ComboFix from one of these locations:* IMPORTANT !!! Save ComboFix.exe to your Desktop making sure you rename it comfix.exe
  • Disable your AntiVirus and AntiSpyware applications including Firewalls, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Comfix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Edited by m0le, 21 May 2011 - 06:07 AM.

Posted Image
m0le is a proud member of UNITE

#5 jackngwen2004

jackngwen2004
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:17 AM

Posted 21 May 2011 - 06:24 PM

Hello m0le, I am having a lot of trouble finding the C:\ComboFix.txt. I think I have found it but cannot figure out a way to get it up on this reply. Can you send me instructions on how to do this please? I let the program finish and it shows me the entire log in a notepad format. I have not found a txt on the desktop or anything else other than the whole layout in notepad form. Thank you for your time. JP

#6 jackngwen2004

jackngwen2004
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:17 AM

Posted 21 May 2011 - 06:31 PM

ComboFix 11-05-21.03 - jackngwen 05/21/2011 17:47:10.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.3043 [GMT -5:00]
Running from: c:\documents and settings\jackngwen\Desktop\comfix.exe.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Jack\WINDOWS
c:\program files\SelectRebates
c:\program files\SelectRebates\FFToolbar\chrome.manifest
c:\program files\SelectRebates\FFToolbar\chrome\sahtoolbar.jar
c:\program files\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js
c:\program files\SelectRebates\FFToolbar\install.rdf
c:\program files\SelectRebates\SelectAlerts.dat
c:\program files\SelectRebates\SelectRebates.ini
c:\program files\SelectRebates\SelectRebatesA.dat
c:\program files\SelectRebates\SelectRebatesB.dat
c:\program files\SelectRebates\SelectRebatesBT.dat
c:\program files\SelectRebates\Toolbar\AddtoList.bmp
c:\program files\SelectRebates\Toolbar\basis.xml
c:\program files\SelectRebates\Toolbar\basis.xml.bak
c:\program files\SelectRebates\Toolbar\Basis.xml.dym
c:\program files\SelectRebates\Toolbar\basis.xml.temp
c:\program files\SelectRebates\Toolbar\Blank.bmp
c:\program files\SelectRebates\Toolbar\CashBack.bmp
c:\program files\SelectRebates\Toolbar\Coupons.bmp
c:\program files\SelectRebates\Toolbar\GroceryCoupon.bmp
c:\program files\SelectRebates\Toolbar\i_magnifying.bmp
c:\program files\SelectRebates\Toolbar\icons.bmp
c:\program files\SelectRebates\Toolbar\ImageCache\alert-red.bmp
c:\program files\SelectRebates\Toolbar\logo.bmp
c:\program files\SelectRebates\Toolbar\logo_24.bmp
c:\program files\SelectRebates\Toolbar\logo_HotSpots.bmp
c:\program files\SelectRebates\Toolbar\ReviewSite.bmp
c:\program files\SelectRebates\Toolbar\RightControls.dym
c:\program files\SelectRebates\Toolbar\Scissors.bmp
.
Infected copy of c:\windows\system32\drivers\volsnap.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2011-04-21 to 2011-05-21 )))))))))))))))))))))))))))))))
.
.
2011-05-01 11:26 . 2011-05-01 11:26 -------- d-sh--w- c:\documents and settings\jackngwen\IECompatCache
2011-05-01 11:18 . 2011-05-01 11:18 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache
2011-04-30 11:07 . 2011-04-30 11:07 -------- d-----w- c:\documents and settings\jackngwen\Local Settings\Application Data\Help
2011-04-26 11:02 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-04-26 11:01 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-04-26 10:55 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-04-26 10:31 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-04-25 12:02 . 2011-04-25 12:02 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2011-04-24 12:35 . 2011-04-24 12:35 -------- d-sh--w- c:\documents and settings\jackngwen\PrivacIE
2011-04-24 11:04 . 2011-04-24 11:04 -------- d-sh--w- c:\documents and settings\jackngwen\IETldCache
2011-04-24 10:38 . 2011-02-22 23:06 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-04-24 10:38 . 2011-02-22 23:06 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-04-24 10:38 . 2011-02-22 23:06 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-04-24 10:38 . 2011-02-22 23:06 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-04-24 10:38 . 2011-02-22 23:06 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-04-24 10:38 . 2011-02-22 23:06 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-04-24 10:38 . 2011-02-22 23:06 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-04-24 02:00 . 2004-08-04 03:41 11868 ------w- c:\windows\system32\drivers\mdmxsdk.sys
2011-04-24 02:00 . 2004-08-04 03:41 1041536 ------w- c:\windows\system32\drivers\hsfdpsp2.sys
2011-04-24 02:00 . 2004-08-04 03:41 685056 ------w- c:\windows\system32\drivers\hsfcxts2.sys
2011-04-24 02:00 . 2004-08-04 03:41 220032 ------w- c:\windows\system32\drivers\hsfbs2s2.sys
2011-04-24 02:00 . 2008-04-14 00:12 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2011-04-24 01:49 . 2000-03-21 05:55 118784 ----a-w- c:\windows\system32\vbalNCSM6.dll
2011-04-24 01:49 . 1999-05-13 06:00 1064456 ----a-w- c:\windows\system32\Mscomctl.ocx
2011-04-24 01:49 . 1999-05-07 06:00 140288 ----a-w- c:\windows\system32\Comdlg32.ocx
2011-04-24 01:49 . 1999-02-19 13:54 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2011-04-24 01:49 . 1999-03-26 05:00 101888 ----a-w- c:\windows\system32\Vb6stkit.dll
2011-04-24 01:49 . 2000-07-17 19:41 70088 ----a-w- c:\windows\system32\Project2-1.ocx
2011-04-24 01:14 . 2011-04-24 01:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Hewlett-Packard
2011-04-24 01:14 . 2004-05-11 16:53 344064 ----a-w- c:\windows\system32\hpvcr70.dll
2011-04-24 01:14 . 2004-05-11 15:53 626960 ----a-r- c:\windows\system32\hpvaut32.dll
2011-04-24 01:14 . 2004-05-11 15:53 487424 ----a-r- c:\windows\system32\hpvcp70.dll
2011-04-24 01:14 . 2004-05-11 15:53 44544 ----a-r- c:\windows\system32\MSXML4a.dll
2011-04-24 01:13 . 2011-04-24 01:13 45056 ----a-r- c:\documents and settings\jackngwen\Application Data\Microsoft\Installer\{457791C5-D702-4143-A7B2-2744BE9573F2}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2011-04-24 01:10 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-04-24 01:10 . 2004-03-18 21:55 65536 ----a-w- c:\windows\system32\HPZipm12.exe
2011-04-24 01:10 . 2004-03-18 21:39 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2011-04-24 01:10 . 2004-03-18 21:39 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2011-04-24 01:10 . 2004-03-18 21:38 61440 ----a-w- c:\windows\system32\HPZinw12.exe
2011-04-24 01:09 . 2004-03-18 21:56 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2011-04-24 01:09 . 2004-03-18 21:53 278584 ----a-w- c:\windows\system32\HPZidr12.dll
2011-04-24 01:09 . 1998-10-29 21:45 306688 ----a-w- c:\windows\IsUninst.exe
2011-04-23 23:09 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-04-23 23:09 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2011-04-23 23:08 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2011-04-23 23:07 . 2010-08-27 08:02 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-04-23 23:07 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-04-23 23:06 . 2011-02-17 13:18 357888 -c----w- c:\windows\system32\dllcache\srv.sys
2011-04-23 23:00 . 2011-02-17 13:18 455936 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-04-23 22:59 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2011-04-23 22:58 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2011-04-23 22:58 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2011-04-23 22:58 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2011-04-23 22:58 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2011-04-23 22:58 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2011-04-23 22:58 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2011-04-23 22:58 . 2010-12-20 17:26 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2011-04-23 22:58 . 2010-12-09 15:15 718336 -c----w- c:\windows\system32\dllcache\ntdll.dll
2011-04-23 22:58 . 2010-12-09 13:42 2148864 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-04-23 22:58 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2011-04-23 22:58 . 2010-12-09 13:38 2192768 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-04-23 22:58 . 2010-12-09 13:07 2027008 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-04-23 22:50 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2011-04-23 22:43 . 2011-04-23 22:43 -------- d-----w- c:\documents and settings\jackngwen\Application Data\Malwarebytes
2011-04-23 22:43 . 2011-04-23 22:43 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2011-04-23 22:31 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2011-04-23 22:29 . 2011-04-23 22:29 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Seagate
2011-04-23 22:28 . 2011-02-17 12:32 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-04-23 22:28 . 2010-07-12 12:55 218112 -c----w- c:\windows\system32\dllcache\wordpad.exe
2011-04-23 22:27 . 2011-04-23 22:27 -------- d-----w- c:\documents and settings\jackngwen\Local Settings\Application Data\Downloaded Installations
2011-04-23 22:26 . 2011-04-23 22:26 -------- d-----w- c:\program files\MSXML 6.0
2011-04-23 21:45 . 2011-04-23 21:45 -------- d-----w- c:\documents and settings\jackngwen\Local Settings\Application Data\Symantec
2011-04-23 21:41 . 2011-05-21 22:19 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Symantec
2011-04-23 11:41 . 2011-04-28 21:19 -------- d-----w- c:\program files\EVGA Precision
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-16 19:42 . 2011-04-16 19:42 73728 ----a-w- c:\windows\ALCFDRTM.EXE
2011-04-16 19:39 . 2011-04-16 19:39 315392 ----a-w- c:\windows\HideWin.exe
2011-03-07 05:33 . 2011-04-16 19:17 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2007-07-27 12:00 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2007-07-27 12:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2007-07-27 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2007-07-27 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2007-07-27 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2007-07-27 12:00 385024 ----a-w- c:\windows\system32\html.iec
2001-03-20 09:52 . 2001-03-20 09:52 362496 ----a-w- c:\program files\quake2.exe
2001-03-19 18:20 . 2001-03-19 18:20 227328 ----a-w- c:\program files\pvrgl.dll
2001-03-19 18:20 . 2001-03-19 18:20 142848 ----a-w- c:\program files\3dfxgl.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 16116224]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-05-25 1957888]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [9/26/2009 2:32 AM 189736]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys --> c:\windows\system32\drivers\nvhda32.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-28 c:\windows\Tasks\WebReg 20110427202402.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2004-05-29 04:47]
.
- - - - ORPHANS REMOVED - - - -
.
Notify-NavLogon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-21 17:56
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-05-21 17:58:44
ComboFix-quarantined-files.txt 2011-05-21 22:58
.
Pre-Run: 111,283,494,912 bytes free
Post-Run: 111,383,187,456 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - A0A0FD9213620395407DD81293A1AE93
Hello mOle, I hope this will do for now as it is the only way I am able to get the ComboFix Log to the reply. Let me know if I can do anytning else to assist with the repair. Thank you for your time and efforts. JP

#7 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:17 AM

Posted 21 May 2011 - 06:31 PM

it shows me the entire log in a notepad format.


If you still have the text file then copy and paste it into your next post.

EDIT: Yep, just like you have done above :)

Edited by m0le, 21 May 2011 - 06:32 PM.

Posted Image
m0le is a proud member of UNITE

#8 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:17 AM

Posted 24 May 2011 - 07:43 PM

That's a rootkit and adware double whammy. Please scan next with ESET

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and check Remove found threats
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image
If no log is generated that means nothing was found. Please let me know if this happens.
Posted Image
m0le is a proud member of UNITE

#9 jackngwen2004

jackngwen2004
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:17 AM

Posted 28 May 2011 - 09:09 AM

C:\System Volume Information\_restore{5B6F9311-71E5-4045-B2F9-E5FEEBBECA18}\RP40\A0021749.sys Win32/Olmasco.E trojan deleted - quarantined
Hello mOle, here is the log that you requested. The scan found one trojan in a Win32 file. I will await your next set of instructions. Once again I thank you for your assistance. JP

#10 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:17 AM

Posted 28 May 2011 - 11:09 AM

That appears to be that. Any problems with the PC at the moment?
Posted Image
m0le is a proud member of UNITE

#11 jackngwen2004

jackngwen2004
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:17 AM

Posted 28 May 2011 - 01:02 PM

Hello mOle, hope all is well, I will have to install the new graphics card and will then be ready to install security anti-virus and malware protection. If I may ask, would you have a preference as to which protection might be recommended? I don't go to any unusual sites etc... The malware that was on this pc was loaded through an e-mail after my brother was hacked and his address book was used by some scumbags to infect all his friends etc... My wife opened it because she did not know that we always use an opening phrase to each other to combat just such a problem. I messed up and listened to a coworker at the plant and used the combofix without supervision. I did not know abot bleepingcomputer or the proper way to utilize the service untill my brother e-mailed and said to get the sites assistance with my problem. One of the original problema I encountered after I got the malware was that I lost a graphics card to the code 10 problem. I ordered another unit since a card can go bad. I installed the new card and all seemed well for about 2-3 weeks then the other card did the same thing that the first card did. It starts having problems on occasion then finally quits and I can't get it back even if I re-install etc... as told to do so by the message in the device manager. It did work the first time I did it and then would not work after it quit again. I am hoping that this might completely cure the problem for me as I am ready to put my laptop back into home only mode again and get back to the much faster desktop unit. I am guessing that it will be ok to install and test the desktop unit now that we have completed the procedure. I will wait for confirmation from you on that and after I get your blessings and hopefully a suggestion on the security programs to use I will set everything up and give this pc a run for its money and see how it responds and does. I thank you once again for your time and efforts on my behalf. JP

#12 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:17 AM

Posted 28 May 2011 - 03:16 PM

A test run would be good. Some recommendations are below. Any questions or problems just post me a reply.

You're clean. Good stuff! :thumbup2:

Let's do some clearing up

Please download ATF Cleaner by Atribune. Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

NB: If you are using Firefox and this has caused page loading problems then please clear your private data. To do this go
to the Tools menu, select Clear Private Data, and then check Cache. Click Clear Private Data Now.

This could also be Clear Recent History or similar

Then close Firefox and then reopen it.



Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
    (For Vista/Windows 7 please click Start -> All Programs -> Accessories -> Run)
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between "Combofix" and "/")
  • Please follow the prompts to uninstall Combofix.
  • You will then receive a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything associated with it.


We Need to Clean Up our Mess
Download and Run OTC

We will now remove the tools we used during this fix using OTC.

  • Download OTC by OldTimer and save it to your desktop.
  • Double click Posted Image icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big Posted Image button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.
------------------------------------------------------------------------------------------------------------------------

Here's some advice on how you can keep your PC clean


Use and update your AntiVirus Software

You must have a good antivirus. There are plenty to choose from but I personally recommend the free options of Avast and Avira Antivir. If you want to purchase a security program then I recommend any of the following: AVG, Norton, McAfee, Kaspersky and ESET Nod32.

It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out. If you use a commercial antivirus program you must make sure you keep renewing your subscription. Otherwise, once your subscription runs out, you may not be able to update the programs virus definitions.


Make sure your applications have all of their updates

Use this next program to check for updates for programs already on your system. Download Security Check by screen317 from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically, make sure that updates on any that are flagged are carried out as soon as possible

It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you. Therefore, it is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Install an AntiSpyware Program

A highly recommended AntiSpyware program is SuperAntiSpyware. You can download the free Home Version. or the Pro version for a 15 day trial period.

Installing this or another recommended program will provide spyware & hijacker protection on your computer alongside your virus protection. You should scan your computer with an AntiSpyware program on a regular basis just as you would an antivirus software.


Finally, here's a treasure trove of antivirus, antimalware and antispyware resources


That's it JP, happy surfing!

Cheers.

m0le
Posted Image
m0le is a proud member of UNITE

#13 jackngwen2004

jackngwen2004
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:17 AM

Posted 29 May 2011 - 10:13 AM

Hello mOle, I am happy to report that all seems to be well once again with my computer. I have done all the aforementioned recommendations you gave me and I installed the new graphics card. All seems to be working. I updated as instructed. I have installed Avast anti-virus, MalwareBytes anti-malware, and Superanti-spyware to hopefully stop any problems before they can start. As I mentioned before, we are only casual users, we do not bank or anything of that nature online (old fashioned I guess you could say). I do have a question if you don't mind. I need to know if I can delete the security check and the online scanner we used. I am once again indebted to you for your patience and help with this problem. I will always use the bleepingcomputer service in the future for all my computer problems. Thank you once again. JP

#14 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:08:17 AM

Posted 29 May 2011 - 01:42 PM

I need to know if I can delete the security check and the online scanner we used.


Yes, you can remove them now :)
Posted Image
m0le is a proud member of UNITE

#15 jackngwen2004

jackngwen2004
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:03:17 AM

Posted 31 May 2011 - 04:16 PM

Hello mOle, Thanks again for all the help all is well as of now. Thank you, JP




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users