Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Plz See Hijack Log


  • This topic is locked This topic is locked
25 replies to this topic

#1 TwIsTeDMoFo

TwIsTeDMoFo

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:02 PM

Posted 29 May 2007 - 10:25 PM

Hi: I'm new to this forum thingy, and my IE keeps popping up unwanted sites, plus I keep getting a"Web page unavailable while offline " message constantly.below is my hijack log. I would really appreciate any help.

Regards

William




Logfile of HijackThis v1.99.1
Scan saved at 11:20:11 PM, on 5/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Willie\Desktop\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Startup: KO Approach.lnk = C:\Program Files\KO Approach\Approach.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1179623094968
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A18EE40-023B-4C21-B145-693D7AC42175}: NameServer = 66.174.95.44 69.78.96.14
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\ddcyaax.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

Attached Files



BC AdBot (Login to Remove)

 


m

#2 TwIsTeDMoFo

TwIsTeDMoFo
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:02 PM

Posted 29 May 2007 - 10:29 PM

Oh almost forgot.. I have run a full scan with the latest virus defenitions for norton internet security 2007, I have run counterspy and spydoctor...and yes it did remove a few items , but the problem remains.


thanks

#3 amateur

amateur

    Malware Fighter


  • Malware Response Team
  • 2,775 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:02 PM

Posted 31 May 2007 - 10:42 AM

Hello and welcome to BC. :thumbsup:

Please download ComboFix

Note: It is important that it is saved directly to your desktop.

Close all browsers.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log for you. Post that log in your next reply along with a fresh HijackThis log taken after a reboot.
  • Note: Do not mouseclick combofix's window while it's running. That may cause it to stall.


#4 TwIsTeDMoFo

TwIsTeDMoFo
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:02 PM

Posted 31 May 2007 - 06:26 PM

K below is my combofix log and I have attached a new hijackthis log as well.


"Willie" - 2007-05-31 19:10:28 Service Pack 2
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Willie\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\akqlrhno.dll
C:\WINDOWS\system32\guqphsme.dll
C:\WINDOWS\system32\oagprsel.dll
C:\WINDOWS\system32\qyrvseos.dll
C:\WINDOWS\system32\srikpjrv.dll
C:\WINDOWS\system32\xwkhtpig.dll
C:\WINDOWS\system32\hjjlm.bak1
C:\WINDOWS\system32\hjjlm.bak2
C:\WINDOWS\system32\hjjlm.ini
C:\WINDOWS\system32\hjjlm.ini2
C:\WINDOWS\system32\hjjlm.tmp
C:\WINDOWS\system32\hjjlm.bak1
C:\WINDOWS\system32\hjjlm.bak2
C:\WINDOWS\system32\hjjlm.ini
C:\WINDOWS\system32\hjjlm.ini2
C:\WINDOWS\system32\hjjlm.tmp
C:\WINDOWS\system32\hjjlm.bak1
C:\WINDOWS\system32\hjjlm.bak2
C:\WINDOWS\system32\hjjlm.ini
C:\WINDOWS\system32\hjjlm.ini2
C:\WINDOWS\system32\hjjlm.tmp
C:\WINDOWS\system32\mljjh.dll
C:\WINDOWS\system32\urqqolj.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((( Files Created from 2007-05-01 to 2007-06-01 ))))))))))))))))))))))))))))))))))


2007-05-29 20:39 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\TrojanHunter
2007-05-29 20:23 <DIR> d-------- C:\Program Files\TrojanHunter 4.6
2007-05-28 23:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-28 15:57 8,443 --a------ C:\WINDOWS\system32\ddcyaax.dll
2007-05-28 15:57 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-05-28 14:47 24,192 --a------ C:\Documents and Settings\Willie\usbsermptxp.sys
2007-05-28 14:47 24,192 --a------ C:\DOCUME~1\Willie\usbsermptxp.sys
2007-05-28 14:47 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys
2007-05-28 14:47 22,768 --a------ C:\Documents and Settings\Willie\usbsermpt.sys
2007-05-28 14:47 22,768 --a------ C:\DOCUME~1\Willie\usbsermpt.sys
2007-05-28 14:42 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2007-05-24 08:51 1,708,032 --a------ C:\WINDOWS\system32\Marine Aquarium 2.scr
2007-05-24 08:51 <DIR> d-------- C:\Program Files\SereneScreen
2007-05-24 05:32 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-05-23 15:16 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-05-23 13:43 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-05-23 05:55 0 --a------ C:\WINDOWS\system32\SBRC.dat
2007-05-23 05:55 0 --a------ C:\WINDOWS\system32\SBFC.dat
2007-05-22 09:31 <DIR> d-------- C:\Program Files\WinAVI Video Capture
2007-05-22 08:03 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\muvee Technologies
2007-05-22 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-05-22 07:53 <DIR> d-------- C:\Program Files\Common Files\muvee Technologies
2007-05-22 07:50 <DIR> d-------- C:\Program Files\QuickTime
2007-05-22 07:50 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-05-22 07:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\muvee Technologies
2007-05-22 05:00 73,728 --a------ C:\WINDOWS\VMInstNT.exe
2007-05-22 05:00 40,960 --a------ C:\WINDOWS\VM303UninstNT.exe
2007-05-22 05:00 219,520 --a------ C:\WINDOWS\system32\drivers\usbvm326.sys
2007-05-22 05:00 192,512 --a------ C:\WINDOWS\VimicroCam.exe
2007-05-22 05:00 <DIR> d-------- C:\WINDOWS\CatRoot
2007-05-22 05:00 <DIR> d-------- C:\Program Files\HP 1.3MP Webcam
2007-05-22 05:00 <DIR> d-------- C:\Program Files\DIFX
2007-05-22 04:45 <DIR> d-------- C:\Program Files\CCleaner
2007-05-22 04:15 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-05-21 11:46 <DIR> d-------- C:\Documents and Settings\Willie\Contacts
2007-05-21 11:46 <DIR> d-------- C:\DOCUME~1\Willie\Contacts
2007-05-21 11:45 <DIR> d-------- C:\Program Files\MSN Messenger
2007-05-21 07:22 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\teamspeak2
2007-05-21 04:30 <DIR> d-------- C:\Program Files\directx
2007-05-21 03:48 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\Smith Micro
2007-05-21 03:45 <DIR> d-------- C:\Program Files\Verizon Wireless
2007-05-21 03:45 <DIR> d-------- C:\Program Files\Novatel Wireless
2007-05-21 01:04 1,156 --a------ C:\WINDOWS\mozver.dat
2007-05-21 00:52 0 --a------ C:\WINDOWS\nsreg.dat
2007-05-21 00:29 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
2007-05-21 00:29 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\CyberLink
2007-05-21 00:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
2007-05-21 00:28 <DIR> d-------- C:\Program Files\CyberLink
2007-05-21 00:21 <DIR> d-------- C:\Program Files\XP Codec Pack
2007-05-21 00:18 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\Yahoo!
2007-05-21 00:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-05-21 00:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
2007-05-21 00:05 <DIR> d-------- C:\Program Files\Yahoo!
2007-05-21 00:03 <DIR> d-------- C:\Program Files\Common Files\Smith Micro Shared
2007-05-21 00:03 <DIR> d-------- C:\Program Files\CheckIt
2007-05-20 14:24 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-05-20 13:43 18,560 --a------ C:\WINDOWS\system32\drivers\vtcdrv.sys
2007-05-20 13:37 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2007-05-20 13:37 1,645,320 --a------ C:\WINDOWS\system32\gdiplus.dll
2007-05-20 13:37 <DIR> d-------- C:\Program Files\Philips
2007-05-20 13:37 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2007-05-20 13:37 <DIR> d-------- C:\Program Files\ArcSoft
2007-05-20 13:37 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\InstallShield
2007-05-20 13:33 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\Google
2007-05-20 13:29 <DIR> d-------- C:\Program Files\Google
2007-05-20 13:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-05-20 13:25 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2007-05-20 13:24 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-05-20 13:23 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-05-20 13:17 <DIR> d-------- C:\Documents and Settings\Willie\Shared
2007-05-20 13:17 <DIR> d-------- C:\Documents and Settings\Willie\Incomplete
2007-05-20 13:17 <DIR> d-------- C:\DOCUME~1\Willie\Shared
2007-05-20 13:17 <DIR> d-------- C:\DOCUME~1\Willie\Incomplete
2007-05-20 13:17 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\LimeWire
2007-05-20 13:07 <DIR> d-------- C:\Program Files\LimeWire
2007-05-20 13:05 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-05-20 13:05 <DIR> d-------- C:\Program Files\MTV Networks
2007-05-20 13:03 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-05-20 13:02 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-05-20 12:59 <DIR> d-------- C:\Program Files\Teamspeak2_RC2
2007-05-20 12:58 18,816 --a------ C:\WINDOWS\system32\drivers\dvd43llh.sys
2007-05-20 12:58 <DIR> d-------- C:\Program Files\dvd43
2007-05-20 12:57 <DIR> d-------- C:\Program Files\Real
2007-05-20 12:57 <DIR> d-------- C:\Program Files\KO Approach
2007-05-20 12:52 <DIR> d-------- C:\Program Files\TGTSoft
2007-05-20 12:22 <DIR> d--hs---- C:\RECYCLER
2007-05-19 20:39 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-05-19 20:34 <DIR> d-------- C:\Program Files\Norton Internet Security
2007-05-19 20:33 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-05-19 20:33 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-05-19 20:32 <DIR> d-------- C:\Program Files\Symantec
2007-05-19 20:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-05-19 20:30 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-05-19 20:27 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-05-19 20:27 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-05-19 20:27 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-05-19 20:27 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-05-19 20:27 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-05-19 20:27 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-05-19 20:27 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-05-19 20:27 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-05-19 20:26 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-05-19 20:04 95,360 --a------ C:\WINDOWS\system32\drivers\atapi.sys
2007-05-19 20:04 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2007-05-19 20:04 7,168 --a------ C:\WINDOWS\system32\hccoin.dll
2007-05-19 20:04 57,600 --a------ C:\WINDOWS\system32\drivers\usbhub.sys
2007-05-19 20:04 5,504 --a------ C:\WINDOWS\system32\drivers\intelide.sys
2007-05-19 20:04 26,624 --a------ C:\WINDOWS\system32\drivers\usbehci.sys
2007-05-19 20:04 25,088 --a------ C:\WINDOWS\system32\drivers\pciidex.sys
2007-05-19 20:04 20,480 --a------ C:\WINDOWS\system32\drivers\usbuhci.sys
2007-05-19 20:04 142,976 --a------ C:\WINDOWS\system32\drivers\usbport.sys
2007-05-19 20:03 68,224 --a------ C:\WINDOWS\system32\drivers\pci.sys
2007-05-19 20:03 35,840 --a------ C:\WINDOWS\system32\drivers\isapnp.sys
2007-05-19 20:03 <DIR> d-------- C:\WINDOWS\system32\ReinstallBackups
2007-05-19 20:03 <DIR> d-------- C:\Program Files\Intel
2007-05-19 20:02 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-05-19 20:01 987,136 --a------ C:\WINDOWS\system32\BttnCmn.dll
2007-05-19 20:01 9,472 --a------ C:\WINDOWS\system32\drivers\CPQBttn.sys
2007-05-19 20:01 8,192 --a------ C:\WINDOWS\system32\drivers\eabfiltr.sys
2007-05-19 20:01 1,560,576 --a------ C:\WINDOWS\system32\BttnCmns_64.dll
2007-05-19 20:01 1,560,576 --a------ C:\WINDOWS\system32\BttnCmns.dll
2007-05-19 20:01 <DIR> d-------- C:\Program Files\Hewlett-Packard
2007-05-19 19:57 <DIR> d-------- C:\Program Files\HPQ
2007-05-19 19:57 <DIR> d-------- C:\Program Files\HP
2007-05-19 19:57 <DIR> d-------- C:\Program Files\Broadcom
2007-05-19 19:55 90,112 --a------ C:\WINDOWS\system32\snymsico.dll
2007-05-19 19:55 51,840 --a------ C:\WINDOWS\system32\drivers\rimsptsk.sys
2007-05-19 19:55 308,992 --a------ C:\WINDOWS\system32\drivers\rixdptsk.sys
2007-05-19 19:55 28,928 --a------ C:\WINDOWS\system32\drivers\rimmptsk.sys
2007-05-19 19:55 16,480 --a------ C:\WINDOWS\system32\rixdicon.dll
2007-05-19 19:55 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-05-19 19:55 <DIR> d-------- C:\swsetup
2007-05-19 19:55 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-05-19 18:58 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-05-19 18:58 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2007-05-19 18:58 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-05-19 18:55 3,407,872 --ah----- C:\Documents and Settings\Willie\NTUSER.DAT
2007-05-19 18:55 3,407,872 --ah----- C:\DOCUME~1\Willie\NTUSER.DAT
2007-05-19 18:55 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-05-19 18:54 262,144 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT
2007-05-19 18:54 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-05-19 18:54 <DIR> d-------- C:\WINDOWS\Prefetch
2007-05-19 18:53 225,280 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-05-19 18:50 225,280 ---h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT
2007-05-19 18:50 <DIR> d-------- C:\WINDOWS\system32\xircom
2007-05-19 18:50 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-05-19 18:49 50 --a------ C:\AUTOEXEC.BAT
2007-05-19 18:49 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2007-05-19 18:49 0 -rahs---- C:\MSDOS.SYS
2007-05-19 18:49 0 -rahs---- C:\IO.SYS
2007-05-19 18:49 0 --a------ C:\CONFIG.SYS
2007-05-19 18:48 <DIR> dr------- C:\WINDOWS\Offline Web Pages
2007-05-19 18:48 <DIR> d--hs---- C:\DOCUME~1\ALLUSE~1\DRM
2007-05-19 18:48 <DIR> d--h----- C:\Program Files\WindowsUpdate
2007-05-19 18:48 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2007-05-19 18:48 <DIR> d-------- C:\WINDOWS\system32\DirectX
2007-05-19 18:47 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2007-05-19 18:47 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2007-05-19 18:47 64,512 --a------ C:\WINDOWS\system32\acctres.dll
2007-05-19 18:47 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2007-05-19 18:47 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-05-19 18:47 53,080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-05-19 18:47 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2007-05-19 18:47 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2007-05-19 18:47 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2007-05-19 18:47 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2007-05-19 18:47 33,624 --a------ C:\WINDOWS\system32\wups.dll
2007-05-19 18:47 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-05-19 18:47 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2007-05-19 18:47 239,104 --a------ C:\WINDOWS\system32\srrstr.dll
2007-05-19 18:47 23,040 --a------ C:\WINDOWS\system32\fltmc.exe
2007-05-19 18:47 203,096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-05-19 18:47 194,328 --a------ C:\WINDOWS\system32\wuaueng1.dll
2007-05-19 18:47 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-05-19 18:47 172,312 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-05-19 18:47 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2007-05-19 18:47 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2007-05-19 18:47 128,896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2007-05-19 18:47 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2007-05-19 18:47 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2007-05-19 18:47 1,710,936 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-05-19 18:47 <DIR> d---s---- C:\WINDOWS\Tasks
2007-05-19 18:47 <DIR> d-------- C:\WINDOWS\system32\Restore
2007-05-19 18:47 <DIR> d-------- C:\WINDOWS\system32\Macromed
2007-05-19 18:47 <DIR> d-------- C:\WINDOWS\srchasst
2007-05-19 18:47 <DIR> d-------- C:\Program Files\Movie Maker
2007-05-19 18:47 <DIR> d-------- C:\Program Files\Common Files\MSSoap
2007-05-19 18:46 81,920 --a------ C:\WINDOWS\system32\isign32.dll
2007-05-19 18:46 81,920 --a------ C:\WINDOWS\system32\ils.dll
2007-05-19 18:46 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2007-05-19 18:46 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys
2007-05-19 18:46 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2007-05-19 18:46 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-19 18:46 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2007-05-19 18:46 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2007-05-19 18:46 48,128 --a------ C:\WINDOWS\system32\inetres.dll
2007-05-19 18:46 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2007-05-19 18:46 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2007-05-19 18:46 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2007-05-19 18:46 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2007-05-19 18:46 274,944 --a------ C:\WINDOWS\system32\mstask.dll
2007-05-19 18:46 274,432 --a------ C:\WINDOWS\system32\inetcfg.dll
2007-05-19 18:46 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2007-05-19 18:46 21,640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-05-19 18:46 190,976 --a------ C:\WINDOWS\system32\schedsvc.dll
2007-05-19 18:46 170,496 --a------ C:\WINDOWS\system32\srsvc.dll
2007-05-19 18:46 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2007-05-19 18:46 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2007-05-19 18:45 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2007-05-19 18:45 9,728 --a------ C:\WINDOWS\system32\reset.exe
2007-05-19 18:45 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2007-05-19 18:45 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-05-19 18:45 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-05-19 18:45 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-05-19 18:45 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2007-05-19 18:45 54,272 --a------ C:\WINDOWS\system32\stclient.dll
2007-05-19 18:45 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-05-19 18:45 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2007-05-19 18:45 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-05-19 18:45 4,096 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2007-05-19 18:45 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2007-05-19 18:45 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-05-19 18:45 33,792 --a------ C:\WINDOWS\system32\regini.exe
2007-05-19 18:45 25,600 --a------ C:\WINDOWS\system32\comaddin.dll
2007-05-19 18:45 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll
2007-05-19 18:45 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2007-05-19 18:45 22,016 --a------ C:\WINDOWS\system32\qwinsta.exe
2007-05-19 18:45 20,992 --a------ C:\WINDOWS\system32\msg.exe
2007-05-19 18:45 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll
2007-05-19 18:45 16,896 --a------ C:\WINDOWS\system32\tsshutdn.exe
2007-05-19 18:45 16,896 --a------ C:\WINDOWS\system32\qappsrv.exe
2007-05-19 18:45 16,384 --a------ C:\WINDOWS\system32\tskill.exe
2007-05-19 18:45 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-05-19 18:45 15,872 --a------ C:\WINDOWS\system32\rwinsta.exe
2007-05-19 18:45 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2007-05-19 18:45 15,360 --a------ C:\WINDOWS\system32\logoff.exe
2007-05-19 18:45 147,456 --a------ C:\WINDOWS\system32\comsnap.dll
2007-05-19 18:45 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2007-05-19 18:45 14,848 --a------ C:\WINDOWS\system32\tscon.exe
2007-05-19 18:45 14,848 --a------ C:\WINDOWS\system32\shadow.exe
2007-05-19 18:45 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-05-19 18:45 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2007-05-19 18:45 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-05-19 18:45 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-05-19 18:45 1,161 --a------ C:\WINDOWS\system32\usrlogon.cmd
2007-05-19 18:45 <DIR> d-------- C:\WINDOWS\Registration
2007-05-19 18:45 <DIR> d-------- C:\Program Files\Online Services
2007-05-19 18:45 <DIR> d-------- C:\Program Files\MSN Gaming Zone
2007-05-19 18:45 <DIR> d-------- C:\Program Files\Messenger
2007-05-19 18:44 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll
2007-05-19 18:44 93,696 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2007-05-19 18:44 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-05-19 18:44 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2007-05-19 18:44 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2007-05-19 18:44 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2007-05-19 18:44 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2007-05-19 18:44 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-05-19 18:44 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2007-05-19 18:44 60,416 --a------ C:\WINDOWS\system32\remotepg.dll
2007-05-19 18:44 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2007-05-19 18:44 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2007-05-19 18:44 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2007-05-19 18:44 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2007-05-19 18:44 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2007-05-19 18:44 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2007-05-19 18:44 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-05-19 18:44 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2007-05-19 18:44 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2007-05-19 18:44 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll
2007-05-19 18:44 407,552 --a------ C:\WINDOWS\system32\mstsc.exe
2007-05-19 18:44 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2007-05-19 18:44 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll
2007-05-19 18:44 347,136 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-05-19 18:44 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-05-19 18:44 295,424 --a------ C:\WINDOWS\system32\termsrv.dll
2007-05-19 18:44 225,792 --a------ C:\WINDOWS\system32\catsrv.dll
2007-05-19 18:44 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2007-05-19 18:44 20,480 --a------ C:\WINDOWS\system32\qprocess.exe
2007-05-19 18:44 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2007-05-19 18:44 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2007-05-19 18:44 185,344 --a------ C:\WINDOWS\system32\cmprops.dll
2007-05-19 18:44 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-05-19 18:44 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2007-05-19 18:44 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2007-05-19 18:44 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2007-05-19 18:44 140,800 --a------ C:\WINDOWS\system32\sessmgr.exe
2007-05-19 18:44 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2007-05-19 18:44 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-05-19 18:44 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2007-05-19 18:44 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-05-19 18:44 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2007-05-19 18:44 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2007-05-19 18:44 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2007-05-19 18:44 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2007-05-19 18:44 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-05-19 18:44 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-05-19 18:44 <DIR> d-------- C:\WINDOWS\system32\MsDtc
2007-05-19 18:44 <DIR> d-------- C:\WINDOWS\system32\Com
2007-05-19 18:44 <DIR> d-------- C:\Program Files\Windows NT
2007-05-19 18:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-05-19 18:11 <DIR> d-------- C:\Program Files\CONEXANT
2007-05-19 18:08 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-05-19 18:07 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-05-19 18:05 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-05-19 18:05 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-05-19 18:04 <DIR> d--hs---- C:\Documents and Settings\Willie\UserData
2007-05-19 18:04 <DIR> d--hs---- C:\DOCUME~1\Willie\UserData
2007-05-19 18:03 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
2007-05-19 18:00 53,248 --a------ C:\WINDOWS\csnp2uvc.dll
2007-05-19 18:00 47,744 --a------ C:\WINDOWS\system32\drivers\snp2uvc.sys
2007-05-19 18:00 26,880 --a------ C:\WINDOWS\system32\drivers\sncduvc.sys
2007-05-19 18:00 102,400 --a------ C:\WINDOWS\system32\vsnp2uvc.dll
2007-05-19 18:00 102,400 --a------ C:\WINDOWS\HPWebcam.exe
2007-05-19 17:53 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-05-19 17:16 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-05-19 17:16 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-05-19 17:16 <DIR> d-------- C:\WINDOWS\nview
2007-05-19 17:16 <DIR> d-------- C:\WINDOWS\NV588344.TMP
2007-05-19 17:13 201,856 --a------ C:\WINDOWS\system32\drivers\SynTP.sys
2007-05-19 17:13 196,608 --a------ C:\WINDOWS\system32\SynCtrl.dll
2007-05-19 17:13 163,840 --a------ C:\WINDOWS\system32\SynCOM.dll
2007-05-19 17:13 143,360 --a------ C:\WINDOWS\system32\SynTPAPI.dll
2007-05-19 17:13 110,592 --a------ C:\WINDOWS\system32\SynTPCo4.dll
2007-05-19 17:13 <DIR> d-------- C:\Program Files\Synaptics
2007-05-19 17:13 <DIR> d-------- C:\Program Files\HP DVB-T TV Tuner
2007-05-19 17:11 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2007-05-19 17:07 561,152 --a------ C:\WINDOWS\system32\NETw3c32.dll
2007-05-19 17:07 53,248 --a------ C:\WINDOWS\iwlandrvxpver.dll
2007-05-19 17:07 2,732,032 --a------ C:\WINDOWS\system32\NETw3r32.dll
2007-05-19 17:07 1,711,488 --a------ C:\WINDOWS\system32\drivers\NETw3x32.sys
2007-05-19 17:07 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-05-19 11:37 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-05-19 11:37 78,464 --a------ C:\WINDOWS\system32\drivers\usbvideo.sys
2007-05-19 11:37 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-05-19 11:37 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-05-19 11:37 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-05-19 11:37 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-05-19 11:37 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-05-19 11:37 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-05-19 11:37 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-05-19 11:37 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-05-19 11:37 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-05-19 11:37 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2007-05-19 11:37 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2007-05-19 11:37 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2007-05-19 11:37 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2007-05-19 11:36 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2007-05-19 11:36 8,832 --a------ C:\WINDOWS\system32\drivers\wmiacpi.sys
2007-05-19 11:36 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2007-05-19 11:36 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2007-05-19 11:36 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys
2007-05-19 11:35 <DIR> dr------- C:\Program Files
2007-05-19 11:35 <DIR> d--hs---- C:\WINDOWS\Installer
2007-05-19 11:35 <DIR> d-------- C:\Program Files\Common Files\SpeechEngines
2007-05-19 11:35 <DIR> d-------- C:\Program Files\Common Files\ODBC
2007-05-19 11:34 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2007-05-19 11:34 9,008 --a------ C:\WINDOWS\system\VER.DLL
2007-05-19 11:34 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2007-05-19 11:34 82,944 --a------ C:\WINDOWS\system\OLECLI.DLL
2007-05-19 11:34 8,704 --a------ C:\WINDOWS\system32\batt.dll
2007-05-19 11:34 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2007-05-19 11:34 74,752 --a------ C:\WINDOWS\system32\storprop.dll
2007-05-19 11:34 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2007-05-19 11:34 69,584 --a------ C:\WINDOWS\system\AVICAP.DLL
2007-05-19 11:34 69,120 --a------ C:\WINDOWS\NOTEPAD.EXE
2007-05-19 11:34 68,768 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdycl.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdsl1.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdsl.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdpl.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdhu.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdcz2.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdcz1.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdcr.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\KBDAL.DLL
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdro.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdpl1.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhu1.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2007-05-19 11:34 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2007-05-19 11:34 32,816 --a------ C:\WINDOWS\system\COMMDLG.DLL
2007-05-19 11:34 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-05-19 11:34 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2007-05-19 11:34 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2007-05-19 11:34 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2007-05-19 11:34 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2007-05-19 11:34 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-05-19 11:34 126,912 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2007-05-19 11:34 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2007-05-19 11:34 109,456 --a------ C:\WINDOWS\system\AVIFILE.DLL
2007-05-19 11:34 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2007-05-19 11:34 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\Documents
2007-05-19 11:34 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-05-19 11:34 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2007-05-19 11:33 <DIR> d--hs---- C:\System Volume Information
2007-05-19 11:33 <DIR> d-------- C:\Documents and Settings
2007-05-19 11:27 <DIR> dr-hsc--- C:\WINDOWS\system32\dllcache
2007-05-19 11:27 <DIR> dr--s---- C:\WINDOWS\Fonts
2007-05-19 11:27 <DIR> dr------- C:\WINDOWS\Web
2007-05-19 11:27 <DIR> d--h----- C:\WINDOWS\inf
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\WinSxS
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\twain_32
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\wins
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\wbem
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\usmt
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\spool
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\ShellExt
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\Setup
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\ras
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\oobe
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\npp
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\mui
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\inetsrv
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\IME
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\icsxml
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\ias
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\export
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\drivers\etc
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\drivers\disdn
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\drivers
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\dhcp
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\config
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\3com_dmi
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\3076
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\2052
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1054
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1042
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1041
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1037
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1033
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1031
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1028
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1025
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\security
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Resources
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\repair
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Provisioning
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\PeerNet
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\pchealth
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\mui
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\msapps
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\msagent
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Media
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\ime
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Help
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\ehome
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Driver Cache
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Debug
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Cursors
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Connection Wizard
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Config
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\AppPatch
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\addins
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-03-27 01:39:14 20,480 ----a-w C:\WINDOWS\system32\ac3config.exe
2007-03-22 03:39:00 1,060,864 ----a-w C:\WINDOWS\system32\MFC71.DLL
2007-03-22 03:33:00 348,160 ----a-w C:\WINDOWS\system32\MSVCR71.DLL
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4efb-9B51-7695ECA05670}=C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-03-20 14:39]
{1E8A6170-7264-4D0F-BEAE-D42A53123C75}=C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-12 00:04]
{5A263CF7-56A6-4D68-A8CF-345BE45BC911}=C:\Program Files\Yahoo!\Search\YSearchSuggest.dll [2007-02-23 16:04]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}=C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 13:33]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl"="%ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" []
"hpWirelessAssistant"="%ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 14:36]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-07-26 22:44 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 00:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2005-12-05 18:04]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 11:31]
"P2kAutostart"="" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wintfj32]
wintfj32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\ddcyaax.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-05-20 03:40:01 C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Willie.job

********************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-31 19:16:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
P2kAutostart = ???

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-05-31 19:17:18 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-31 19:17

--- E O F ---

Attached Files



#5 amateur

amateur

    Malware Fighter


  • Malware Response Team
  • 2,775 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:02 PM

Posted 31 May 2007 - 07:38 PM

Hi,

Open notepad and copy/paste the text inside the codebox below into it. Make sure the wordwrap in Format menu is turned off:
File::
C:\WINDOWS\system32\ddcyaax.dll

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wintfj32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"appinit_dlls"=-

Save this as ComboFix-Do.txt Posted Image
Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe

Then, please run Combofix one more time and post the log along with the other logs requested below.

=======================================

Please download Ccleaner and save it to your desktop.
Tutorial for CCleaner
During the installation be sure to UN-check the box for "Ccleaner Yahoo Toolbar" unless you want it. Do not scan with it yet.

=======================================

Download AVG Anti Spyware

Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows"

Posted Image
  • Install AVG Anti Spyware
  • Double-click the icon on Desktop to launch AVG
  • On the top of the main screen click Shield
  • Click the word active to change it to inactive
  • On the top of the main screen click Update.
  • Then click on Start Update. The update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
  • Select "Automatically generate report after every scan"
  • Un-Select "Only if threats were found"
When you have finished updating, EXIT AVG Anti Spyware. Do Not run a scan just yet, we will shortly.

========================================

Reboot your computer in Safe Mode using the F8 method below.
a. If the computer is running, shut down Windows, and then turn off the power.
b. Wait 30 seconds, and then turn the computer on.
c. Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
d. Ensure that the Safe Mode option is selected.
e. Press Enter. The computer then begins to start in Safe mode.

=======================================

From Safe Mode run Ccleaner
  • Click on Options,
  • Select Advanced
  • Now UNCHECK "Only delete files in Windows Temp folders older than 48 hours"
  • Make sure the Cleaner block on the left is selected.
  • Do not use the "Issues" block . It's meant for professionals.
  • Choose the Windows tab.
  • Check everything EXCEPT Advanced part of the Menu.
  • Click on "Analyze". This process could take a while.
  • If you don't want to loose your login passwords to certain sites, click on Options
  • Select cookies and move the ones you want to keep to the "cookies to keep" section, by highlighting and using the arrows in the middle.
  • Choose Run Cleaner.
When CCleaner shows how much has been removed, cleaning is finished. Click Exit.
If you have more than one users, run Ccleaner for every user

========================================

IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Launch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, **Please ensure it is set to Quarantine then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close AVG Anti-Spyware.
=========================================

Reboot in Normal Mode.

=========================================

Perform an online scan using Internet Explorer with Panda ActiveScan
  • Click on Posted Image located at the bottom of the page.
  • A "pop up" window will appear. Please ensure that your pop up blocker doesn't block it
  • Enter your e-mail address, country, and state & click "Free Online Scan" The download of the 8 MB Panda's ActiveX control will take place
Begin the scan by selecting Posted Image
  • If it finds any malware, it will offer you a report.
  • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
  • Click on Posted Image then click Posted Image and post back the contents please.

==========================================

Please post back the results from AVG Anti-Spyware and Panda online scans, latest Combofix log, and a fresh HijackThis log.
Let me know how the computer is behaving now.

#6 TwIsTeDMoFo

TwIsTeDMoFo
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:02 PM

Posted 01 June 2007 - 11:02 AM

OK, The AVG spyware check found nothing, now when I went to the panda site using firefox it did not let me run the scan. It said browser not compatable, so I tried IE, and oh boy when I clicked on the free online scan I started getting pop-up after pop-up so I did not do that one. But while using firefox and surfing online I dont get the IE pop-ups anymore. I have attached a new hijack log and the combofix log.

Attached Files



#7 TwIsTeDMoFo

TwIsTeDMoFo
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:02 PM

Posted 01 June 2007 - 11:03 AM

Oh the ccleaner found a few cookies 6 items and cleaned it up..I just forgot to add this to my above reply. :thumbsup:

#8 amateur

amateur

    Malware Fighter


  • Malware Response Team
  • 2,775 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:02 PM

Posted 01 June 2007 - 01:13 PM

Hi,

so I tried IE, and oh boy when I clicked on the free online scan I started getting pop-up after pop-up so I did not do that one

Hmmmm.... that's not a good sign. I'm checking your logs. In the mean time stay away from IE. Will get back to you soon.

#9 amateur

amateur

    Malware Fighter


  • Malware Response Team
  • 2,775 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:02 PM

Posted 01 June 2007 - 01:44 PM

Hi,

Looks like you've been re-infected. Have you been downloading anything? I noticed that you use file sharing programs like Limewire. I think the nature of P2P filesharing is so that even if one is using a "clean" program, many of the files downloaded from non-documented sources have the potential of being infected. So, regardless of whether one is using a "clean" program, one may still be prone to infection by malware. It will still bring malware into your system because more than half of all files available for download from peer-to-peer networks have been deliberately infected with some form of malware. I recommend that you remove it from your system via Add/Remove Programs in Control Panel.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow again the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

===================================

Remove the old copy of the Combofix and get a fresh Copy.

Please download ComboFix

Note: It is important that it is saved directly to your desktop.

Close all browsers.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log for you. Post that log in your next reply
  • Note: Do not mouseclick combofix's window while it's running. That may cause it to stall.
===================================

Restart your computer.

===================================

Scan with HijackThis again and post the fresh log along with the vundofix.txt and the combofix.txt. Please do not attach them. Use several posts if necessary. Thank you.

Edited by amateur, 01 June 2007 - 02:50 PM.


#10 amateur

amateur

    Malware Fighter


  • Malware Response Team
  • 2,775 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:02 PM

Posted 01 June 2007 - 02:49 PM

When you're done with the above instructions please do this as well:

Go to My Computer> Tools> Folder Options> View>"Uncheck" Hide protected operating system files. Click Apply>OK.

===============================

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log


#11 TwIsTeDMoFo

TwIsTeDMoFo
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:02 PM

Posted 01 June 2007 - 03:37 PM

ok below r the first three logs, (Vundo , Combo & Hijack log)I will do SDFIX right after this and will post sdfix log with new hijack log as well


VundoFix V6.4.1

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 4:01:52 PM 6/1/2007

Listing files found while scanning....

C:\WINDOWS\gihknn.ini
C:\WINDOWS\nnkhig.dll

Beginning removal...

Attempting to delete C:\WINDOWS\gihknn.ini
C:\WINDOWS\gihknn.ini Has been deleted!

Attempting to delete C:\WINDOWS\nnkhig.dll
C:\WINDOWS\nnkhig.dll Has been deleted!

Performing Repairs to the registry.
Done!




"Willie" - 2007-06-01 16:20:22 Service Pack 2
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Willie\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


"C:\WINDOWS\system32\tmp3.tmp.dll"


((((((((((((((((((((((((((((((( Files Created from 2007-05-01 to 2007-06-01 ))))))))))))))))))))))))))))))))))


2007-06-01 16:01 <DIR> d-------- C:\VundoFix Backups
2007-06-01 11:16 233,468 --a------ C:\DOCUME~1\Willie\APPLIC~1\tmp5.tmp.exe
2007-06-01 11:16 17,010 --a------ C:\DOCUME~1\Willie\APPLIC~1\tmp4.tmp.exe
2007-06-01 11:15 51,017 --a------ C:\DOCUME~1\Willie\APPLIC~1\tmp3.tmp.exe
2007-05-31 19:22 47,989 --a------ C:\WINDOWS\system32\jkhfe.exe
2007-05-31 19:22 37,474 --a------ C:\WINDOWS\system32\isigtpp.dll
2007-05-31 19:17 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-05-29 20:39 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\TrojanHunter
2007-05-29 20:23 <DIR> d-------- C:\Program Files\TrojanHunter 4.6
2007-05-28 23:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-28 15:57 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-05-28 14:47 24,192 --a------ C:\Documents and Settings\Willie\usbsermptxp.sys
2007-05-28 14:47 24,192 --a------ C:\DOCUME~1\Willie\usbsermptxp.sys
2007-05-28 14:47 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys
2007-05-28 14:47 22,768 --a------ C:\Documents and Settings\Willie\usbsermpt.sys
2007-05-28 14:47 22,768 --a------ C:\DOCUME~1\Willie\usbsermpt.sys
2007-05-28 14:42 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2007-05-24 08:51 1,708,032 --a------ C:\WINDOWS\system32\Marine Aquarium 2.scr
2007-05-24 08:51 <DIR> d-------- C:\Program Files\SereneScreen
2007-05-24 05:32 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-05-23 15:16 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-05-23 13:43 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-05-23 05:55 0 --a------ C:\WINDOWS\system32\SBRC.dat
2007-05-23 05:55 0 --a------ C:\WINDOWS\system32\SBFC.dat
2007-05-22 09:31 <DIR> d-------- C:\Program Files\WinAVI Video Capture
2007-05-22 08:03 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\muvee Technologies
2007-05-22 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-05-22 07:53 <DIR> d-------- C:\Program Files\Common Files\muvee Technologies
2007-05-22 07:50 <DIR> d-------- C:\Program Files\QuickTime
2007-05-22 07:50 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-05-22 07:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\muvee Technologies
2007-05-22 05:00 73,728 --a------ C:\WINDOWS\VMInstNT.exe
2007-05-22 05:00 40,960 --a------ C:\WINDOWS\VM303UninstNT.exe
2007-05-22 05:00 219,520 --a------ C:\WINDOWS\system32\drivers\usbvm326.sys
2007-05-22 05:00 192,512 --a------ C:\WINDOWS\VimicroCam.exe
2007-05-22 05:00 <DIR> d-------- C:\WINDOWS\CatRoot
2007-05-22 05:00 <DIR> d-------- C:\Program Files\HP 1.3MP Webcam
2007-05-22 05:00 <DIR> d-------- C:\Program Files\DIFX
2007-05-22 04:45 <DIR> d-------- C:\Program Files\CCleaner
2007-05-22 04:15 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-05-21 11:46 <DIR> d-------- C:\Documents and Settings\Willie\Contacts
2007-05-21 11:46 <DIR> d-------- C:\DOCUME~1\Willie\Contacts
2007-05-21 11:45 <DIR> d-------- C:\Program Files\MSN Messenger
2007-05-21 07:22 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\teamspeak2
2007-05-21 04:30 <DIR> d-------- C:\Program Files\directx
2007-05-21 03:48 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\Smith Micro
2007-05-21 03:45 <DIR> d-------- C:\Program Files\Verizon Wireless
2007-05-21 03:45 <DIR> d-------- C:\Program Files\Novatel Wireless
2007-05-21 01:04 1,156 --a------ C:\WINDOWS\mozver.dat
2007-05-21 00:52 0 --a------ C:\WINDOWS\nsreg.dat
2007-05-21 00:29 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
2007-05-21 00:29 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\CyberLink
2007-05-21 00:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
2007-05-21 00:28 <DIR> d-------- C:\Program Files\CyberLink
2007-05-21 00:21 <DIR> d-------- C:\Program Files\XP Codec Pack
2007-05-21 00:18 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\Yahoo!
2007-05-21 00:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-05-21 00:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
2007-05-21 00:05 <DIR> d-------- C:\Program Files\Yahoo!
2007-05-21 00:03 <DIR> d-------- C:\Program Files\Common Files\Smith Micro Shared
2007-05-21 00:03 <DIR> d-------- C:\Program Files\CheckIt
2007-05-20 14:24 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-05-20 13:43 18,560 --a------ C:\WINDOWS\system32\drivers\vtcdrv.sys
2007-05-20 13:37 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2007-05-20 13:37 1,645,320 --a------ C:\WINDOWS\system32\gdiplus.dll
2007-05-20 13:37 <DIR> d-------- C:\Program Files\Philips
2007-05-20 13:37 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2007-05-20 13:37 <DIR> d-------- C:\Program Files\ArcSoft
2007-05-20 13:37 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\InstallShield
2007-05-20 13:33 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\Google
2007-05-20 13:29 <DIR> d-------- C:\Program Files\Google
2007-05-20 13:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-05-20 13:25 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2007-05-20 13:24 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-05-20 13:23 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-05-20 13:17 <DIR> d-------- C:\Documents and Settings\Willie\Shared
2007-05-20 13:17 <DIR> d-------- C:\Documents and Settings\Willie\Incomplete
2007-05-20 13:17 <DIR> d-------- C:\DOCUME~1\Willie\Shared
2007-05-20 13:17 <DIR> d-------- C:\DOCUME~1\Willie\Incomplete
2007-05-20 13:17 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\LimeWire
2007-05-20 13:05 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-05-20 13:05 <DIR> d-------- C:\Program Files\MTV Networks
2007-05-20 13:03 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-05-20 13:02 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-05-20 12:59 <DIR> d-------- C:\Program Files\Teamspeak2_RC2
2007-05-20 12:57 <DIR> d-------- C:\Program Files\Real
2007-05-20 12:57 <DIR> d-------- C:\Program Files\KO Approach
2007-05-20 12:52 <DIR> d-------- C:\Program Files\TGTSoft
2007-05-20 12:22 <DIR> d--hs---- C:\RECYCLER
2007-05-19 20:39 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-05-19 20:34 <DIR> d-------- C:\Program Files\Norton Internet Security
2007-05-19 20:33 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-05-19 20:33 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-05-19 20:32 <DIR> d-------- C:\Program Files\Symantec
2007-05-19 20:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-05-19 20:30 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-05-19 20:27 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-05-19 20:27 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-05-19 20:27 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-05-19 20:27 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-05-19 20:27 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-05-19 20:27 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-05-19 20:27 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-05-19 20:27 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-05-19 20:26 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-05-19 20:04 95,360 --a------ C:\WINDOWS\system32\drivers\atapi.sys
2007-05-19 20:04 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2007-05-19 20:04 7,168 --a------ C:\WINDOWS\system32\hccoin.dll
2007-05-19 20:04 57,600 --a------ C:\WINDOWS\system32\drivers\usbhub.sys
2007-05-19 20:04 5,504 --a------ C:\WINDOWS\system32\drivers\intelide.sys
2007-05-19 20:04 26,624 --a------ C:\WINDOWS\system32\drivers\usbehci.sys
2007-05-19 20:04 25,088 --a------ C:\WINDOWS\system32\drivers\pciidex.sys
2007-05-19 20:04 20,480 --a------ C:\WINDOWS\system32\drivers\usbuhci.sys
2007-05-19 20:04 142,976 --a------ C:\WINDOWS\system32\drivers\usbport.sys
2007-05-19 20:03 68,224 --a------ C:\WINDOWS\system32\drivers\pci.sys
2007-05-19 20:03 35,840 --a------ C:\WINDOWS\system32\drivers\isapnp.sys
2007-05-19 20:03 <DIR> d-------- C:\WINDOWS\system32\ReinstallBackups
2007-05-19 20:03 <DIR> d-------- C:\Program Files\Intel
2007-05-19 20:02 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-05-19 20:01 987,136 --a------ C:\WINDOWS\system32\BttnCmn.dll
2007-05-19 20:01 9,472 --a------ C:\WINDOWS\system32\drivers\CPQBttn.sys
2007-05-19 20:01 8,192 --a------ C:\WINDOWS\system32\drivers\eabfiltr.sys
2007-05-19 20:01 1,560,576 --a------ C:\WINDOWS\system32\BttnCmns_64.dll
2007-05-19 20:01 1,560,576 --a------ C:\WINDOWS\system32\BttnCmns.dll
2007-05-19 20:01 <DIR> d-------- C:\Program Files\Hewlett-Packard
2007-05-19 19:57 <DIR> d-------- C:\Program Files\HPQ
2007-05-19 19:57 <DIR> d-------- C:\Program Files\HP
2007-05-19 19:57 <DIR> d-------- C:\Program Files\Broadcom
2007-05-19 19:55 90,112 --a------ C:\WINDOWS\system32\snymsico.dll
2007-05-19 19:55 51,840 --a------ C:\WINDOWS\system32\drivers\rimsptsk.sys
2007-05-19 19:55 308,992 --a------ C:\WINDOWS\system32\drivers\rixdptsk.sys
2007-05-19 19:55 28,928 --a------ C:\WINDOWS\system32\drivers\rimmptsk.sys
2007-05-19 19:55 16,480 --a------ C:\WINDOWS\system32\rixdicon.dll
2007-05-19 19:55 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-05-19 19:55 <DIR> d-------- C:\swsetup
2007-05-19 19:55 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-05-19 18:58 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-05-19 18:58 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2007-05-19 18:58 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-05-19 18:55 3,407,872 --ah----- C:\Documents and Settings\Willie\NTUSER.DAT
2007-05-19 18:55 3,407,872 --ah----- C:\DOCUME~1\Willie\NTUSER.DAT
2007-05-19 18:55 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-05-19 18:54 262,144 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT
2007-05-19 18:54 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-05-19 18:54 <DIR> d-------- C:\WINDOWS\Prefetch
2007-05-19 18:53 225,280 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-05-19 18:50 225,280 ---h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT
2007-05-19 18:50 <DIR> d-------- C:\WINDOWS\system32\xircom
2007-05-19 18:50 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-05-19 18:49 50 --a------ C:\AUTOEXEC.BAT
2007-05-19 18:49 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2007-05-19 18:49 0 -rahs---- C:\MSDOS.SYS
2007-05-19 18:49 0 -rahs---- C:\IO.SYS
2007-05-19 18:49 0 --a------ C:\CONFIG.SYS
2007-05-19 18:48 <DIR> dr------- C:\WINDOWS\Offline Web Pages
2007-05-19 18:48 <DIR> d--hs---- C:\DOCUME~1\ALLUSE~1\DRM
2007-05-19 18:48 <DIR> d--h----- C:\Program Files\WindowsUpdate
2007-05-19 18:48 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2007-05-19 18:48 <DIR> d-------- C:\WINDOWS\system32\DirectX
2007-05-19 18:47 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2007-05-19 18:47 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2007-05-19 18:47 64,512 --a------ C:\WINDOWS\system32\acctres.dll
2007-05-19 18:47 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2007-05-19 18:47 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-05-19 18:47 53,080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-05-19 18:47 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2007-05-19 18:47 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2007-05-19 18:47 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2007-05-19 18:47 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2007-05-19 18:47 33,624 --a------ C:\WINDOWS\system32\wups.dll
2007-05-19 18:47 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-05-19 18:47 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2007-05-19 18:47 239,104 --a------ C:\WINDOWS\system32\srrstr.dll
2007-05-19 18:47 23,040 --a------ C:\WINDOWS\system32\fltmc.exe
2007-05-19 18:47 203,096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-05-19 18:47 194,328 --a------ C:\WINDOWS\system32\wuaueng1.dll
2007-05-19 18:47 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-05-19 18:47 172,312 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-05-19 18:47 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2007-05-19 18:47 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2007-05-19 18:47 128,896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2007-05-19 18:47 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2007-05-19 18:47 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2007-05-19 18:47 1,710,936 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-05-19 18:47 <DIR> d---s---- C:\WINDOWS\Tasks
2007-05-19 18:47 <DIR> d-------- C:\WINDOWS\system32\Restore
2007-05-19 18:47 <DIR> d-------- C:\WINDOWS\system32\Macromed
2007-05-19 18:47 <DIR> d-------- C:\WINDOWS\srchasst
2007-05-19 18:47 <DIR> d-------- C:\Program Files\Movie Maker
2007-05-19 18:47 <DIR> d-------- C:\Program Files\Common Files\MSSoap
2007-05-19 18:46 81,920 --a------ C:\WINDOWS\system32\isign32.dll
2007-05-19 18:46 81,920 --a------ C:\WINDOWS\system32\ils.dll
2007-05-19 18:46 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2007-05-19 18:46 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys
2007-05-19 18:46 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2007-05-19 18:46 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-19 18:46 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2007-05-19 18:46 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2007-05-19 18:46 48,128 --a------ C:\WINDOWS\system32\inetres.dll
2007-05-19 18:46 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2007-05-19 18:46 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2007-05-19 18:46 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2007-05-19 18:46 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2007-05-19 18:46 274,944 --a------ C:\WINDOWS\system32\mstask.dll
2007-05-19 18:46 274,432 --a------ C:\WINDOWS\system32\inetcfg.dll
2007-05-19 18:46 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2007-05-19 18:46 21,640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-05-19 18:46 190,976 --a------ C:\WINDOWS\system32\schedsvc.dll
2007-05-19 18:46 170,496 --a------ C:\WINDOWS\system32\srsvc.dll
2007-05-19 18:46 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2007-05-19 18:46 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2007-05-19 18:45 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2007-05-19 18:45 9,728 --a------ C:\WINDOWS\system32\reset.exe
2007-05-19 18:45 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2007-05-19 18:45 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-05-19 18:45 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-05-19 18:45 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-05-19 18:45 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2007-05-19 18:45 54,272 --a------ C:\WINDOWS\system32\stclient.dll
2007-05-19 18:45 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-05-19 18:45 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2007-05-19 18:45 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-05-19 18:45 4,096 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2007-05-19 18:45 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2007-05-19 18:45 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-05-19 18:45 33,792 --a------ C:\WINDOWS\system32\regini.exe
2007-05-19 18:45 25,600 --a------ C:\WINDOWS\system32\comaddin.dll
2007-05-19 18:45 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll
2007-05-19 18:45 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2007-05-19 18:45 22,016 --a------ C:\WINDOWS\system32\qwinsta.exe
2007-05-19 18:45 20,992 --a------ C:\WINDOWS\system32\msg.exe
2007-05-19 18:45 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll
2007-05-19 18:45 16,896 --a------ C:\WINDOWS\system32\tsshutdn.exe
2007-05-19 18:45 16,896 --a------ C:\WINDOWS\system32\qappsrv.exe
2007-05-19 18:45 16,384 --a------ C:\WINDOWS\system32\tskill.exe
2007-05-19 18:45 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-05-19 18:45 15,872 --a------ C:\WINDOWS\system32\rwinsta.exe
2007-05-19 18:45 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2007-05-19 18:45 15,360 --a------ C:\WINDOWS\system32\logoff.exe
2007-05-19 18:45 147,456 --a------ C:\WINDOWS\system32\comsnap.dll
2007-05-19 18:45 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2007-05-19 18:45 14,848 --a------ C:\WINDOWS\system32\tscon.exe
2007-05-19 18:45 14,848 --a------ C:\WINDOWS\system32\shadow.exe
2007-05-19 18:45 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-05-19 18:45 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2007-05-19 18:45 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-05-19 18:45 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-05-19 18:45 1,161 --a------ C:\WINDOWS\system32\usrlogon.cmd
2007-05-19 18:45 <DIR> d-------- C:\WINDOWS\Registration
2007-05-19 18:45 <DIR> d-------- C:\Program Files\Online Services
2007-05-19 18:45 <DIR> d-------- C:\Program Files\MSN Gaming Zone
2007-05-19 18:45 <DIR> d-------- C:\Program Files\Messenger
2007-05-19 18:44 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll
2007-05-19 18:44 93,696 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2007-05-19 18:44 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-05-19 18:44 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2007-05-19 18:44 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2007-05-19 18:44 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2007-05-19 18:44 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2007-05-19 18:44 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-05-19 18:44 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2007-05-19 18:44 60,416 --a------ C:\WINDOWS\system32\remotepg.dll
2007-05-19 18:44 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2007-05-19 18:44 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2007-05-19 18:44 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2007-05-19 18:44 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2007-05-19 18:44 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2007-05-19 18:44 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2007-05-19 18:44 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-05-19 18:44 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2007-05-19 18:44 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2007-05-19 18:44 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll
2007-05-19 18:44 407,552 --a------ C:\WINDOWS\system32\mstsc.exe
2007-05-19 18:44 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2007-05-19 18:44 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll
2007-05-19 18:44 347,136 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-05-19 18:44 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-05-19 18:44 295,424 --a------ C:\WINDOWS\system32\termsrv.dll
2007-05-19 18:44 225,792 --a------ C:\WINDOWS\system32\catsrv.dll
2007-05-19 18:44 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2007-05-19 18:44 20,480 --a------ C:\WINDOWS\system32\qprocess.exe
2007-05-19 18:44 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2007-05-19 18:44 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2007-05-19 18:44 185,344 --a------ C:\WINDOWS\system32\cmprops.dll
2007-05-19 18:44 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-05-19 18:44 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2007-05-19 18:44 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2007-05-19 18:44 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2007-05-19 18:44 140,800 --a------ C:\WINDOWS\system32\sessmgr.exe
2007-05-19 18:44 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2007-05-19 18:44 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-05-19 18:44 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2007-05-19 18:44 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-05-19 18:44 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2007-05-19 18:44 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2007-05-19 18:44 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2007-05-19 18:44 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2007-05-19 18:44 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-05-19 18:44 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-05-19 18:44 <DIR> d-------- C:\WINDOWS\system32\MsDtc
2007-05-19 18:44 <DIR> d-------- C:\WINDOWS\system32\Com
2007-05-19 18:44 <DIR> d-------- C:\Program Files\Windows NT
2007-05-19 18:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-05-19 18:11 <DIR> d-------- C:\Program Files\CONEXANT
2007-05-19 18:08 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-05-19 18:07 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-05-19 18:05 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-05-19 18:05 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-05-19 18:04 <DIR> d--hs---- C:\Documents and Settings\Willie\UserData
2007-05-19 18:04 <DIR> d--hs---- C:\DOCUME~1\Willie\UserData
2007-05-19 18:03 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
2007-05-19 18:00 53,248 --a------ C:\WINDOWS\csnp2uvc.dll
2007-05-19 18:00 47,744 --a------ C:\WINDOWS\system32\drivers\snp2uvc.sys
2007-05-19 18:00 26,880 --a------ C:\WINDOWS\system32\drivers\sncduvc.sys
2007-05-19 18:00 102,400 --a------ C:\WINDOWS\system32\vsnp2uvc.dll
2007-05-19 18:00 102,400 --a------ C:\WINDOWS\HPWebcam.exe
2007-05-19 17:53 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-05-19 17:16 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-05-19 17:16 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-05-19 17:16 <DIR> d-------- C:\WINDOWS\nview
2007-05-19 17:16 <DIR> d-------- C:\WINDOWS\NV588344.TMP
2007-05-19 17:13 201,856 --a------ C:\WINDOWS\system32\drivers\SynTP.sys
2007-05-19 17:13 196,608 --a------ C:\WINDOWS\system32\SynCtrl.dll
2007-05-19 17:13 163,840 --a------ C:\WINDOWS\system32\SynCOM.dll
2007-05-19 17:13 143,360 --a------ C:\WINDOWS\system32\SynTPAPI.dll
2007-05-19 17:13 110,592 --a------ C:\WINDOWS\system32\SynTPCo4.dll
2007-05-19 17:13 <DIR> d-------- C:\Program Files\Synaptics
2007-05-19 17:13 <DIR> d-------- C:\Program Files\HP DVB-T TV Tuner
2007-05-19 17:11 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2007-05-19 17:07 561,152 --a------ C:\WINDOWS\system32\NETw3c32.dll
2007-05-19 17:07 53,248 --a------ C:\WINDOWS\iwlandrvxpver.dll
2007-05-19 17:07 2,732,032 --a------ C:\WINDOWS\system32\NETw3r32.dll
2007-05-19 17:07 1,711,488 --a------ C:\WINDOWS\system32\drivers\NETw3x32.sys
2007-05-19 17:07 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-05-19 11:37 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-05-19 11:37 78,464 --a------ C:\WINDOWS\system32\drivers\usbvideo.sys
2007-05-19 11:37 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-05-19 11:37 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-05-19 11:37 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-05-19 11:37 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-05-19 11:37 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-05-19 11:37 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-05-19 11:37 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-05-19 11:37 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-05-19 11:37 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-05-19 11:37 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2007-05-19 11:37 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2007-05-19 11:37 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2007-05-19 11:37 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2007-05-19 11:36 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2007-05-19 11:36 8,832 --a------ C:\WINDOWS\system32\drivers\wmiacpi.sys
2007-05-19 11:36 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2007-05-19 11:36 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2007-05-19 11:36 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys
2007-05-19 11:35 <DIR> dr------- C:\Program Files
2007-05-19 11:35 <DIR> d--hs---- C:\WINDOWS\Installer
2007-05-19 11:35 <DIR> d-------- C:\Program Files\Common Files\SpeechEngines
2007-05-19 11:35 <DIR> d-------- C:\Program Files\Common Files\ODBC
2007-05-19 11:34 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2007-05-19 11:34 9,008 --a------ C:\WINDOWS\system\VER.DLL
2007-05-19 11:34 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2007-05-19 11:34 82,944 --a------ C:\WINDOWS\system\OLECLI.DLL
2007-05-19 11:34 8,704 --a------ C:\WINDOWS\system32\batt.dll
2007-05-19 11:34 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2007-05-19 11:34 74,752 --a------ C:\WINDOWS\system32\storprop.dll
2007-05-19 11:34 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2007-05-19 11:34 69,584 --a------ C:\WINDOWS\system\AVICAP.DLL
2007-05-19 11:34 69,120 --a------ C:\WINDOWS\NOTEPAD.EXE
2007-05-19 11:34 68,768 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdycl.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdsl1.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdsl.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdpl.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdhu.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdcz2.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdcz1.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdcr.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\KBDAL.DLL
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdro.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdpl1.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhu1.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2007-05-19 11:34 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2007-05-19 11:34 32,816 --a------ C:\WINDOWS\system\COMMDLG.DLL
2007-05-19 11:34 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-05-19 11:34 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2007-05-19 11:34 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2007-05-19 11:34 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2007-05-19 11:34 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2007-05-19 11:34 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-05-19 11:34 126,912 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2007-05-19 11:34 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2007-05-19 11:34 109,456 --a------ C:\WINDOWS\system\AVIFILE.DLL
2007-05-19 11:34 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2007-05-19 11:34 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\Documents
2007-05-19 11:34 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-05-19 11:34 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2007-05-19 11:33 <DIR> d--hs---- C:\System Volume Information
2007-05-19 11:33 <DIR> d-------- C:\Documents and Settings
2007-05-19 11:27 <DIR> dr-hsc--- C:\WINDOWS\system32\dllcache
2007-05-19 11:27 <DIR> dr--s---- C:\WINDOWS\Fonts
2007-05-19 11:27 <DIR> dr------- C:\WINDOWS\Web
2007-05-19 11:27 <DIR> d--h----- C:\WINDOWS\inf
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\WinSxS
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\twain_32
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\wins
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\wbem
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\usmt
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\spool
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\ShellExt
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\Setup
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\ras
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\oobe
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\npp
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\mui
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\inetsrv
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\IME
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\icsxml
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\ias
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\export
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\drivers\etc
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\drivers\disdn
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\drivers
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\dhcp
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\config
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\3com_dmi
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\3076
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\2052
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1054
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1042
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1041
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1037
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1033
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1031
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1028
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1025
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\security
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Resources
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\repair
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Provisioning
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\PeerNet
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\pchealth
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\mui
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\msapps
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\msagent
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Media
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\ime
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Help
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\ehome
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Driver Cache
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Debug
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Cursors
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Connection Wizard
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Config
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\AppPatch
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\addins
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-03-27 01:39:14 20,480 ----a-w C:\WINDOWS\system32\ac3config.exe
2007-03-22 03:39:00 1,060,864 ----a-w C:\WINDOWS\system32\MFC71.DLL
2007-03-22 03:33:00 348,160 ----a-w C:\WINDOWS\system32\MSVCR71.DLL
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4efb-9B51-7695ECA05670}=C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-03-20 14:39]
{1E8A6170-7264-4D0F-BEAE-D42A53123C75}=C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-12 00:04]
{5A263CF7-56A6-4D68-A8CF-345BE45BC911}=C:\Program Files\Yahoo!\Search\YSearchSuggest.dll [2007-02-23 16:04]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}=C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 13:33]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{a0eadf42-f9da-4b05-87cb-37d5759b34d7}=C:\WINDOWS\system32\isigtpp.dll [2007-05-31 19:22]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl"="%ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" []
"hpWirelessAssistant"="%ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 14:36]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-07-26 22:44 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 00:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 11:31]
"P2kAutostart"="" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\isigtpp]
isigtpp.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-05-20 03:40:01 C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Willie.job

********************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-01 16:22:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
P2kAutostart = ???

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-06-01 16:22:29
C:\ComboFix-quarantined-files.txt ... 2007-06-01 16:22
C:\ComboFix2.txt ... 2007-05-31 21:21
C:\ComboFix3.txt ... 2007-05-31 19:17

--- E O F ---



Logfile of HijackThis v1.99.1
Scan saved at 4:24:02 PM, on 6/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
C:\Program Files\KO Approach\Approach.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Willie\Desktop\virus remover tools\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {a0eadf42-f9da-4b05-87cb-37d5759b34d7} - C:\WINDOWS\system32\isigtpp.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Startup: KO Approach.lnk = C:\Program Files\KO Approach\Approach.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1179623094968
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A18EE40-023B-4C21-B145-693D7AC42175}: NameServer = 66.174.95.44 66.174.92.14
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: isigtpp - C:\WINDOWS\SYSTEM32\isigtpp.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

#12 TwIsTeDMoFo

TwIsTeDMoFo
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:02 PM

Posted 01 June 2007 - 04:06 PM

Ok below are the last 2 reports you asked for ...The SDFix report and a new hijack log :thumbsup:




SDFix: Version 1.85

Run by Willie - Fri 06/01/2007 - 16:52:05.85

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\Willie\Desktop\SDFix

Safe Mode:
Checking Services:






Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

No Trojan Files Found




Removing Temp Files...

ADS Check:

Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.

Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.



Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
---------------


Checking For Files with Hidden Attributes:

C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp

Finished



Logfile of HijackThis v1.99.1
Scan saved at 4:57:57 PM, on 6/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
C:\Program Files\KO Approach\Approach.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Documents and Settings\Willie\Desktop\virus remover tools\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {a0eadf42-f9da-4b05-87cb-37d5759b34d7} - C:\WINDOWS\system32\isigtpp.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Startup: KO Approach.lnk = C:\Program Files\KO Approach\Approach.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1179623094968
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: isigtpp - C:\WINDOWS\SYSTEM32\isigtpp.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

#13 amateur

amateur

    Malware Fighter


  • Malware Response Team
  • 2,775 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:02 PM

Posted 01 June 2007 - 04:28 PM

Hi,

Before fixing anything, please download the Suspicious File Packer : http://www.safer-networking.org/files/sfp.zip
Unzip it to the desktop and run it.
Paste the following filepaths into the Suspicious File Packer window:

C:\DOCUME~1\Willie\APPLIC~1\tmp5.tmp.exe
C:\DOCUME~1\Willie\APPLIC~1\tmp4.tmp.exe
C:\DOCUME~1\Willie\APPLIC~1\tmp3.tmp.exe
C:\WINDOWS\system32\jkhfe.exe
C:\WINDOWS\system32\isigtpp.dll
C:\WINDOWS\system32\isigtpp.dll


Allow SFP to pack the files. This will generate a CAB archive on your desktop.
Please submit it to this site : http://www.bleepingcomputer.com/submit-malware.php?channel=4
Please include a link to this topic in the message.

================================

Open notepad and copy/paste the text in the quotebox below into it. Please make sure the wordwrap is turned off in Format menu:

File::
C:\DOCUME~1\Willie\APPLIC~1\tmp5.tmp.exe
C:\DOCUME~1\Willie\APPLIC~1\tmp4.tmp.exe
C:\DOCUME~1\Willie\APPLIC~1\tmp3.tmp.exe
C:\WINDOWS\system32\jkhfe.exe
C:\WINDOWS\system32\isigtpp.dll
C:\WINDOWS\system32\isigtpp.dll

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{a0eadf42-f9da-4b05-87cb-37d5759b34d7}=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\isigtpp]

Save this as ComboFix-Do.txt Posted Image
Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe

=================================

You are going to run Vundofix again but a little differently this time.

" Double-click VundoFix.exe to run it.
" Click the Scan for Vundo button.
" Once it's done scanning, click the Remove Vundo button.
" In case it says that nothing has been found, Right click the list box (white box) in the main VundoFix window.
" Select "Add More Files?" from the menu that comes up. This will open a new VundoFix window.
" In the Window: copy and paste next in the first field: C:\WINDOWS\system32\isigtpp.dll
" Click the "Add Files" button.
" Click the "Close Window" button.
" Click the Remove Vundo button.
" You will receive a prompt asking if you want to remove the files, click YES
" Once you click yes, your desktop will go blank as it starts removing Vundo.
" When completed, it will prompt that it will shutdown your computer, click OK.
" Turn your computer back on.

Note: It is possible that VundoFix encounteres a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

================================

Run Combofix again.

================================

Restart your computer. Post the latest comboFix log, VundoFix log and a fresh HijackThis log taken after the restart.

Edited by amateur, 01 June 2007 - 04:30 PM.


#14 TwIsTeDMoFo

TwIsTeDMoFo
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:02 PM

Posted 01 June 2007 - 05:34 PM

ok I downloaded filpacker and sent files with topic link to the addy u provided, also below are the 3 logs u asked for...combo, vundo and hijack


"Willie" - 2007-06-01 18:21:30 Service Pack 2
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Willie\Desktop\"


((((((((((((((((((((((((((((((( Files Created from 2007-05-02 to 2007-06-02 ))))))))))))))))))))))))))))))))))


2007-06-01 16:01 <DIR> d-------- C:\VundoFix Backups
2007-05-31 19:17 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-05-29 20:39 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\TrojanHunter
2007-05-29 20:23 <DIR> d-------- C:\Program Files\TrojanHunter 4.6
2007-05-28 23:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-28 15:57 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-05-28 14:47 24,192 --a------ C:\Documents and Settings\Willie\usbsermptxp.sys
2007-05-28 14:47 24,192 --a------ C:\DOCUME~1\Willie\usbsermptxp.sys
2007-05-28 14:47 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys
2007-05-28 14:47 22,768 --a------ C:\Documents and Settings\Willie\usbsermpt.sys
2007-05-28 14:47 22,768 --a------ C:\DOCUME~1\Willie\usbsermpt.sys
2007-05-28 14:42 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2007-05-24 08:51 1,708,032 --a------ C:\WINDOWS\system32\Marine Aquarium 2.scr
2007-05-24 08:51 <DIR> d-------- C:\Program Files\SereneScreen
2007-05-24 05:32 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-05-23 15:16 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-05-23 13:43 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-05-23 05:55 0 --a------ C:\WINDOWS\system32\SBRC.dat
2007-05-23 05:55 0 --a------ C:\WINDOWS\system32\SBFC.dat
2007-05-22 09:31 <DIR> d-------- C:\Program Files\WinAVI Video Capture
2007-05-22 08:03 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\muvee Technologies
2007-05-22 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-05-22 07:53 <DIR> d-------- C:\Program Files\Common Files\muvee Technologies
2007-05-22 07:50 <DIR> d-------- C:\Program Files\QuickTime
2007-05-22 07:50 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-05-22 07:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\muvee Technologies
2007-05-22 05:00 73,728 --a------ C:\WINDOWS\VMInstNT.exe
2007-05-22 05:00 40,960 --a------ C:\WINDOWS\VM303UninstNT.exe
2007-05-22 05:00 219,520 --a------ C:\WINDOWS\system32\drivers\usbvm326.sys
2007-05-22 05:00 192,512 --a------ C:\WINDOWS\VimicroCam.exe
2007-05-22 05:00 <DIR> d-------- C:\WINDOWS\CatRoot
2007-05-22 05:00 <DIR> d-------- C:\Program Files\HP 1.3MP Webcam
2007-05-22 05:00 <DIR> d-------- C:\Program Files\DIFX
2007-05-22 04:45 <DIR> d-------- C:\Program Files\CCleaner
2007-05-22 04:15 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-05-21 11:46 <DIR> d-------- C:\Documents and Settings\Willie\Contacts
2007-05-21 11:46 <DIR> d-------- C:\DOCUME~1\Willie\Contacts
2007-05-21 11:45 <DIR> d-------- C:\Program Files\MSN Messenger
2007-05-21 07:22 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\teamspeak2
2007-05-21 04:30 <DIR> d-------- C:\Program Files\directx
2007-05-21 03:48 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\Smith Micro
2007-05-21 03:45 <DIR> d-------- C:\Program Files\Verizon Wireless
2007-05-21 03:45 <DIR> d-------- C:\Program Files\Novatel Wireless
2007-05-21 01:04 1,156 --a------ C:\WINDOWS\mozver.dat
2007-05-21 00:52 0 --a------ C:\WINDOWS\nsreg.dat
2007-05-21 00:29 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
2007-05-21 00:29 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\CyberLink
2007-05-21 00:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
2007-05-21 00:28 <DIR> d-------- C:\Program Files\CyberLink
2007-05-21 00:21 <DIR> d-------- C:\Program Files\XP Codec Pack
2007-05-21 00:18 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\Yahoo!
2007-05-21 00:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-05-21 00:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
2007-05-21 00:05 <DIR> d-------- C:\Program Files\Yahoo!
2007-05-21 00:03 <DIR> d-------- C:\Program Files\Common Files\Smith Micro Shared
2007-05-21 00:03 <DIR> d-------- C:\Program Files\CheckIt
2007-05-20 14:24 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-05-20 13:43 18,560 --a------ C:\WINDOWS\system32\drivers\vtcdrv.sys
2007-05-20 13:37 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2007-05-20 13:37 1,645,320 --a------ C:\WINDOWS\system32\gdiplus.dll
2007-05-20 13:37 <DIR> d-------- C:\Program Files\Philips
2007-05-20 13:37 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2007-05-20 13:37 <DIR> d-------- C:\Program Files\ArcSoft
2007-05-20 13:37 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\InstallShield
2007-05-20 13:33 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\Google
2007-05-20 13:29 <DIR> d-------- C:\Program Files\Google
2007-05-20 13:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-05-20 13:25 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2007-05-20 13:24 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-05-20 13:23 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-05-20 13:17 <DIR> d-------- C:\Documents and Settings\Willie\Shared
2007-05-20 13:17 <DIR> d-------- C:\Documents and Settings\Willie\Incomplete
2007-05-20 13:17 <DIR> d-------- C:\DOCUME~1\Willie\Shared
2007-05-20 13:17 <DIR> d-------- C:\DOCUME~1\Willie\Incomplete
2007-05-20 13:17 <DIR> d-------- C:\DOCUME~1\Willie\APPLIC~1\LimeWire
2007-05-20 13:05 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-05-20 13:05 <DIR> d-------- C:\Program Files\MTV Networks
2007-05-20 13:03 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-05-20 13:02 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-05-20 12:59 <DIR> d-------- C:\Program Files\Teamspeak2_RC2
2007-05-20 12:57 <DIR> d-------- C:\Program Files\Real
2007-05-20 12:57 <DIR> d-------- C:\Program Files\KO Approach
2007-05-20 12:52 <DIR> d-------- C:\Program Files\TGTSoft
2007-05-20 12:22 <DIR> d--hs---- C:\RECYCLER
2007-05-19 20:39 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-05-19 20:34 <DIR> d-------- C:\Program Files\Norton Internet Security
2007-05-19 20:33 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-05-19 20:33 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-05-19 20:32 <DIR> d-------- C:\Program Files\Symantec
2007-05-19 20:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-05-19 20:30 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-05-19 20:27 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-05-19 20:27 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-05-19 20:27 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-05-19 20:27 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-05-19 20:27 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-05-19 20:27 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-05-19 20:27 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-05-19 20:27 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-05-19 20:26 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-05-19 20:04 95,360 --a------ C:\WINDOWS\system32\drivers\atapi.sys
2007-05-19 20:04 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2007-05-19 20:04 7,168 --a------ C:\WINDOWS\system32\hccoin.dll
2007-05-19 20:04 57,600 --a------ C:\WINDOWS\system32\drivers\usbhub.sys
2007-05-19 20:04 5,504 --a------ C:\WINDOWS\system32\drivers\intelide.sys
2007-05-19 20:04 26,624 --a------ C:\WINDOWS\system32\drivers\usbehci.sys
2007-05-19 20:04 25,088 --a------ C:\WINDOWS\system32\drivers\pciidex.sys
2007-05-19 20:04 20,480 --a------ C:\WINDOWS\system32\drivers\usbuhci.sys
2007-05-19 20:04 142,976 --a------ C:\WINDOWS\system32\drivers\usbport.sys
2007-05-19 20:03 68,224 --a------ C:\WINDOWS\system32\drivers\pci.sys
2007-05-19 20:03 35,840 --a------ C:\WINDOWS\system32\drivers\isapnp.sys
2007-05-19 20:03 <DIR> d-------- C:\WINDOWS\system32\ReinstallBackups
2007-05-19 20:03 <DIR> d-------- C:\Program Files\Intel
2007-05-19 20:02 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-05-19 20:01 987,136 --a------ C:\WINDOWS\system32\BttnCmn.dll
2007-05-19 20:01 9,472 --a------ C:\WINDOWS\system32\drivers\CPQBttn.sys
2007-05-19 20:01 8,192 --a------ C:\WINDOWS\system32\drivers\eabfiltr.sys
2007-05-19 20:01 1,560,576 --a------ C:\WINDOWS\system32\BttnCmns_64.dll
2007-05-19 20:01 1,560,576 --a------ C:\WINDOWS\system32\BttnCmns.dll
2007-05-19 20:01 <DIR> d-------- C:\Program Files\Hewlett-Packard
2007-05-19 19:57 <DIR> d-------- C:\Program Files\HPQ
2007-05-19 19:57 <DIR> d-------- C:\Program Files\HP
2007-05-19 19:57 <DIR> d-------- C:\Program Files\Broadcom
2007-05-19 19:55 90,112 --a------ C:\WINDOWS\system32\snymsico.dll
2007-05-19 19:55 51,840 --a------ C:\WINDOWS\system32\drivers\rimsptsk.sys
2007-05-19 19:55 308,992 --a------ C:\WINDOWS\system32\drivers\rixdptsk.sys
2007-05-19 19:55 28,928 --a------ C:\WINDOWS\system32\drivers\rimmptsk.sys
2007-05-19 19:55 16,480 --a------ C:\WINDOWS\system32\rixdicon.dll
2007-05-19 19:55 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-05-19 19:55 <DIR> d-------- C:\swsetup
2007-05-19 19:55 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-05-19 18:58 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-05-19 18:58 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2007-05-19 18:58 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-05-19 18:55 3,407,872 --ah----- C:\Documents and Settings\Willie\NTUSER.DAT
2007-05-19 18:55 3,407,872 --ah----- C:\DOCUME~1\Willie\NTUSER.DAT
2007-05-19 18:55 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-05-19 18:54 262,144 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT
2007-05-19 18:54 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-05-19 18:54 <DIR> d-------- C:\WINDOWS\Prefetch
2007-05-19 18:53 225,280 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-05-19 18:50 225,280 ---h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT
2007-05-19 18:50 <DIR> d-------- C:\WINDOWS\system32\xircom
2007-05-19 18:50 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-05-19 18:49 50 --a------ C:\AUTOEXEC.BAT
2007-05-19 18:49 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2007-05-19 18:49 0 -rahs---- C:\MSDOS.SYS
2007-05-19 18:49 0 -rahs---- C:\IO.SYS
2007-05-19 18:49 0 --a------ C:\CONFIG.SYS
2007-05-19 18:48 <DIR> dr------- C:\WINDOWS\Offline Web Pages
2007-05-19 18:48 <DIR> d--hs---- C:\DOCUME~1\ALLUSE~1\DRM
2007-05-19 18:48 <DIR> d--h----- C:\Program Files\WindowsUpdate
2007-05-19 18:48 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2007-05-19 18:48 <DIR> d-------- C:\WINDOWS\system32\DirectX
2007-05-19 18:47 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2007-05-19 18:47 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2007-05-19 18:47 64,512 --a------ C:\WINDOWS\system32\acctres.dll
2007-05-19 18:47 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2007-05-19 18:47 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-05-19 18:47 53,080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-05-19 18:47 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2007-05-19 18:47 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2007-05-19 18:47 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2007-05-19 18:47 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2007-05-19 18:47 33,624 --a------ C:\WINDOWS\system32\wups.dll
2007-05-19 18:47 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-05-19 18:47 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2007-05-19 18:47 239,104 --a------ C:\WINDOWS\system32\srrstr.dll
2007-05-19 18:47 23,040 --a------ C:\WINDOWS\system32\fltmc.exe
2007-05-19 18:47 203,096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-05-19 18:47 194,328 --a------ C:\WINDOWS\system32\wuaueng1.dll
2007-05-19 18:47 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-05-19 18:47 172,312 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-05-19 18:47 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2007-05-19 18:47 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2007-05-19 18:47 128,896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2007-05-19 18:47 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2007-05-19 18:47 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2007-05-19 18:47 1,710,936 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-05-19 18:47 <DIR> d---s---- C:\WINDOWS\Tasks
2007-05-19 18:47 <DIR> d-------- C:\WINDOWS\system32\Restore
2007-05-19 18:47 <DIR> d-------- C:\WINDOWS\system32\Macromed
2007-05-19 18:47 <DIR> d-------- C:\WINDOWS\srchasst
2007-05-19 18:47 <DIR> d-------- C:\Program Files\Movie Maker
2007-05-19 18:47 <DIR> d-------- C:\Program Files\Common Files\MSSoap
2007-05-19 18:46 81,920 --a------ C:\WINDOWS\system32\isign32.dll
2007-05-19 18:46 81,920 --a------ C:\WINDOWS\system32\ils.dll
2007-05-19 18:46 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2007-05-19 18:46 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys
2007-05-19 18:46 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2007-05-19 18:46 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-19 18:46 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2007-05-19 18:46 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2007-05-19 18:46 48,128 --a------ C:\WINDOWS\system32\inetres.dll
2007-05-19 18:46 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2007-05-19 18:46 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2007-05-19 18:46 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2007-05-19 18:46 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2007-05-19 18:46 274,944 --a------ C:\WINDOWS\system32\mstask.dll
2007-05-19 18:46 274,432 --a------ C:\WINDOWS\system32\inetcfg.dll
2007-05-19 18:46 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2007-05-19 18:46 21,640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-05-19 18:46 190,976 --a------ C:\WINDOWS\system32\schedsvc.dll
2007-05-19 18:46 170,496 --a------ C:\WINDOWS\system32\srsvc.dll
2007-05-19 18:46 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2007-05-19 18:46 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2007-05-19 18:45 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2007-05-19 18:45 9,728 --a------ C:\WINDOWS\system32\reset.exe
2007-05-19 18:45 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2007-05-19 18:45 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2007-05-19 18:45 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2007-05-19 18:45 56,832 --a------ C:\WINDOWS\system32\sol.exe
2007-05-19 18:45 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2007-05-19 18:45 54,272 --a------ C:\WINDOWS\system32\stclient.dll
2007-05-19 18:45 5,632 --a------ C:\WINDOWS\system32\write.exe
2007-05-19 18:45 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2007-05-19 18:45 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2007-05-19 18:45 4,096 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2007-05-19 18:45 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2007-05-19 18:45 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2007-05-19 18:45 33,792 --a------ C:\WINDOWS\system32\regini.exe
2007-05-19 18:45 25,600 --a------ C:\WINDOWS\system32\comaddin.dll
2007-05-19 18:45 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll
2007-05-19 18:45 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2007-05-19 18:45 22,016 --a------ C:\WINDOWS\system32\qwinsta.exe
2007-05-19 18:45 20,992 --a------ C:\WINDOWS\system32\msg.exe
2007-05-19 18:45 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll
2007-05-19 18:45 16,896 --a------ C:\WINDOWS\system32\tsshutdn.exe
2007-05-19 18:45 16,896 --a------ C:\WINDOWS\system32\qappsrv.exe
2007-05-19 18:45 16,384 --a------ C:\WINDOWS\system32\tskill.exe
2007-05-19 18:45 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2007-05-19 18:45 15,872 --a------ C:\WINDOWS\system32\rwinsta.exe
2007-05-19 18:45 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2007-05-19 18:45 15,360 --a------ C:\WINDOWS\system32\logoff.exe
2007-05-19 18:45 147,456 --a------ C:\WINDOWS\system32\comsnap.dll
2007-05-19 18:45 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2007-05-19 18:45 14,848 --a------ C:\WINDOWS\system32\tscon.exe
2007-05-19 18:45 14,848 --a------ C:\WINDOWS\system32\shadow.exe
2007-05-19 18:45 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2007-05-19 18:45 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2007-05-19 18:45 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2007-05-19 18:45 114,688 --a------ C:\WINDOWS\system32\calc.exe
2007-05-19 18:45 1,161 --a------ C:\WINDOWS\system32\usrlogon.cmd
2007-05-19 18:45 <DIR> d-------- C:\WINDOWS\Registration
2007-05-19 18:45 <DIR> d-------- C:\Program Files\Online Services
2007-05-19 18:45 <DIR> d-------- C:\Program Files\MSN Gaming Zone
2007-05-19 18:45 <DIR> d-------- C:\Program Files\Messenger
2007-05-19 18:44 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll
2007-05-19 18:44 93,696 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2007-05-19 18:44 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-05-19 18:44 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2007-05-19 18:44 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2007-05-19 18:44 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2007-05-19 18:44 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2007-05-19 18:44 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-05-19 18:44 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2007-05-19 18:44 60,416 --a------ C:\WINDOWS\system32\remotepg.dll
2007-05-19 18:44 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2007-05-19 18:44 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2007-05-19 18:44 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2007-05-19 18:44 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2007-05-19 18:44 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2007-05-19 18:44 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2007-05-19 18:44 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-05-19 18:44 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2007-05-19 18:44 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2007-05-19 18:44 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll
2007-05-19 18:44 407,552 --a------ C:\WINDOWS\system32\mstsc.exe
2007-05-19 18:44 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2007-05-19 18:44 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll
2007-05-19 18:44 347,136 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-05-19 18:44 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-05-19 18:44 295,424 --a------ C:\WINDOWS\system32\termsrv.dll
2007-05-19 18:44 225,792 --a------ C:\WINDOWS\system32\catsrv.dll
2007-05-19 18:44 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2007-05-19 18:44 20,480 --a------ C:\WINDOWS\system32\qprocess.exe
2007-05-19 18:44 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2007-05-19 18:44 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2007-05-19 18:44 185,344 --a------ C:\WINDOWS\system32\cmprops.dll
2007-05-19 18:44 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-05-19 18:44 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2007-05-19 18:44 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2007-05-19 18:44 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2007-05-19 18:44 140,800 --a------ C:\WINDOWS\system32\sessmgr.exe
2007-05-19 18:44 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2007-05-19 18:44 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-05-19 18:44 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2007-05-19 18:44 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-05-19 18:44 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2007-05-19 18:44 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2007-05-19 18:44 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2007-05-19 18:44 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2007-05-19 18:44 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-05-19 18:44 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-05-19 18:44 <DIR> d-------- C:\WINDOWS\system32\MsDtc
2007-05-19 18:44 <DIR> d-------- C:\WINDOWS\system32\Com
2007-05-19 18:44 <DIR> d-------- C:\Program Files\Windows NT
2007-05-19 18:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-05-19 18:11 <DIR> d-------- C:\Program Files\CONEXANT
2007-05-19 18:08 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-05-19 18:07 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-05-19 18:05 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-05-19 18:05 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-05-19 18:04 <DIR> d--hs---- C:\Documents and Settings\Willie\UserData
2007-05-19 18:04 <DIR> d--hs---- C:\DOCUME~1\Willie\UserData
2007-05-19 18:03 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
2007-05-19 18:00 53,248 --a------ C:\WINDOWS\csnp2uvc.dll
2007-05-19 18:00 47,744 --a------ C:\WINDOWS\system32\drivers\snp2uvc.sys
2007-05-19 18:00 26,880 --a------ C:\WINDOWS\system32\drivers\sncduvc.sys
2007-05-19 18:00 102,400 --a------ C:\WINDOWS\system32\vsnp2uvc.dll
2007-05-19 18:00 102,400 --a------ C:\WINDOWS\HPWebcam.exe
2007-05-19 17:53 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-05-19 17:16 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-05-19 17:16 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-05-19 17:16 <DIR> d-------- C:\WINDOWS\nview
2007-05-19 17:16 <DIR> d-------- C:\WINDOWS\NV588344.TMP
2007-05-19 17:13 201,856 --a------ C:\WINDOWS\system32\drivers\SynTP.sys
2007-05-19 17:13 196,608 --a------ C:\WINDOWS\system32\SynCtrl.dll
2007-05-19 17:13 163,840 --a------ C:\WINDOWS\system32\SynCOM.dll
2007-05-19 17:13 143,360 --a------ C:\WINDOWS\system32\SynTPAPI.dll
2007-05-19 17:13 110,592 --a------ C:\WINDOWS\system32\SynTPCo4.dll
2007-05-19 17:13 <DIR> d-------- C:\Program Files\Synaptics
2007-05-19 17:13 <DIR> d-------- C:\Program Files\HP DVB-T TV Tuner
2007-05-19 17:11 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2007-05-19 17:07 561,152 --a------ C:\WINDOWS\system32\NETw3c32.dll
2007-05-19 17:07 53,248 --a------ C:\WINDOWS\iwlandrvxpver.dll
2007-05-19 17:07 2,732,032 --a------ C:\WINDOWS\system32\NETw3r32.dll
2007-05-19 17:07 1,711,488 --a------ C:\WINDOWS\system32\drivers\NETw3x32.sys
2007-05-19 17:07 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-05-19 11:37 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-05-19 11:37 78,464 --a------ C:\WINDOWS\system32\drivers\usbvideo.sys
2007-05-19 11:37 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-05-19 11:37 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-05-19 11:37 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-05-19 11:37 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-05-19 11:37 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-05-19 11:37 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-05-19 11:37 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-05-19 11:37 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-05-19 11:37 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-05-19 11:37 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2007-05-19 11:37 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2007-05-19 11:37 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2007-05-19 11:37 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2007-05-19 11:36 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2007-05-19 11:36 8,832 --a------ C:\WINDOWS\system32\drivers\wmiacpi.sys
2007-05-19 11:36 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2007-05-19 11:36 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2007-05-19 11:36 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys
2007-05-19 11:35 <DIR> dr------- C:\Program Files
2007-05-19 11:35 <DIR> d--hs---- C:\WINDOWS\Installer
2007-05-19 11:35 <DIR> d-------- C:\Program Files\Common Files\SpeechEngines
2007-05-19 11:35 <DIR> d-------- C:\Program Files\Common Files\ODBC
2007-05-19 11:34 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2007-05-19 11:34 9,008 --a------ C:\WINDOWS\system\VER.DLL
2007-05-19 11:34 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2007-05-19 11:34 82,944 --a------ C:\WINDOWS\system\OLECLI.DLL
2007-05-19 11:34 8,704 --a------ C:\WINDOWS\system32\batt.dll
2007-05-19 11:34 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2007-05-19 11:34 74,752 --a------ C:\WINDOWS\system32\storprop.dll
2007-05-19 11:34 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2007-05-19 11:34 69,584 --a------ C:\WINDOWS\system\AVICAP.DLL
2007-05-19 11:34 69,120 --a------ C:\WINDOWS\NOTEPAD.EXE
2007-05-19 11:34 68,768 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdycl.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdsl1.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdsl.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdpl.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdhu.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdcz2.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdcz1.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\kbdcr.dll
2007-05-19 11:34 6,656 -ra------ C:\WINDOWS\system32\KBDAL.DLL
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2007-05-19 11:34 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdro.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdpl1.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhu1.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2007-05-19 11:34 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2007-05-19 11:34 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2007-05-19 11:34 32,816 --a------ C:\WINDOWS\system\COMMDLG.DLL
2007-05-19 11:34 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-05-19 11:34 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2007-05-19 11:34 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2007-05-19 11:34 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2007-05-19 11:34 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2007-05-19 11:34 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-05-19 11:34 126,912 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2007-05-19 11:34 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2007-05-19 11:34 109,456 --a------ C:\WINDOWS\system\AVIFILE.DLL
2007-05-19 11:34 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2007-05-19 11:34 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\Documents
2007-05-19 11:34 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-05-19 11:34 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2007-05-19 11:33 <DIR> d--hs---- C:\System Volume Information
2007-05-19 11:33 <DIR> d-------- C:\Documents and Settings
2007-05-19 11:27 <DIR> dr-hsc--- C:\WINDOWS\system32\dllcache
2007-05-19 11:27 <DIR> dr--s---- C:\WINDOWS\Fonts
2007-05-19 11:27 <DIR> dr------- C:\WINDOWS\Web
2007-05-19 11:27 <DIR> d--h----- C:\WINDOWS\inf
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\WinSxS
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\twain_32
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\wins
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\wbem
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\usmt
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\spool
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\ShellExt
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\Setup
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\ras
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\oobe
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\npp
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\mui
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\inetsrv
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\IME
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\icsxml
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\ias
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\export
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\drivers\etc
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\drivers\disdn
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\drivers
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\dhcp
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\config
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\3com_dmi
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\3076
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\2052
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1054
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1042
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1041
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1037
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1033
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1031
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1028
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32\1025
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system32
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\system
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\security
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Resources
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\repair
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Provisioning
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\PeerNet
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\pchealth
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\mui
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\msapps
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\msagent
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Media
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\ime
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Help
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\ehome
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Driver Cache
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Debug
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Cursors
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Connection Wizard
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\Config
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\AppPatch
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS\addins
2007-05-19 11:27 <DIR> d-------- C:\WINDOWS


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-03-27 01:39:14 20,480 ----a-w C:\WINDOWS\system32\ac3config.exe
2007-03-22 03:39:00 1,060,864 ----a-w C:\WINDOWS\system32\MFC71.DLL
2007-03-22 03:33:00 348,160 ----a-w C:\WINDOWS\system32\MSVCR71.DLL
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4efb-9B51-7695ECA05670}=C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-03-20 14:39]
{1E8A6170-7264-4D0F-BEAE-D42A53123C75}=C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-12 00:04]
{5A263CF7-56A6-4D68-A8CF-345BE45BC911}=C:\Program Files\Yahoo!\Search\YSearchSuggest.dll [2007-02-23 16:04]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}=C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 13:33]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{a0eadf42-f9da-4b05-87cb-37d5759b34d7}=C:\WINDOWS\system32\isigtpp.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl"="%ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" []
"hpWirelessAssistant"="%ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 14:36]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-07-26 22:44 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 00:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 11:31]
"P2kAutostart"="" []

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

*Newly Created Service* - COMHOST

Contents of the 'Scheduled Tasks' folder
2007-05-20 03:40:01 C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Willie.job

********************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-01 18:22:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
P2kAutostart = ???

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-06-01 18:23:15
C:\ComboFix-quarantined-files.txt ... 2007-06-01 18:23
C:\ComboFix2.txt ... 2007-06-01 17:46
C:\ComboFix3.txt ... 2007-06-01 16:22

--- E O F ---



VundoFix V6.4.1

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 4:01:52 PM 6/1/2007

Listing files found while scanning....

C:\WINDOWS\gihknn.ini
C:\WINDOWS\nnkhig.dll

Beginning removal...

Attempting to delete C:\WINDOWS\gihknn.ini
C:\WINDOWS\gihknn.ini Has been deleted!

Attempting to delete C:\WINDOWS\nnkhig.dll
C:\WINDOWS\nnkhig.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.4.1

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 6:02:43 PM 6/1/2007

Listing files found while scanning....

No infected files were found.


Beginning removal...

Performing Repairs to the registry.
Done!


Logfile of HijackThis v1.99.1
Scan saved at 6:27:00 PM, on 6/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
C:\Program Files\KO Approach\Approach.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Willie\Desktop\virus remover tools\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {a0eadf42-f9da-4b05-87cb-37d5759b34d7} - C:\WINDOWS\system32\isigtpp.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Startup: KO Approach.lnk = C:\Program Files\KO Approach\Approach.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1179623094968
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A18EE40-023B-4C21-B145-693D7AC42175}: NameServer = 66.174.95.44 66.174.92.14
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

#15 amateur

amateur

    Malware Fighter


  • Malware Response Team
  • 2,775 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:02 PM

Posted 01 June 2007 - 06:54 PM

Hi,

Ok. It's looking much better now. Just as I was replying to you we had a thunderstorm and lost the power and internet for a while.

Scan with HijackThis again and put a checkmark against the following entries:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {a0eadf42-f9da-4b05-87cb-37d5759b34d7} - C:\WINDOWS\system32\isigtpp.dll (file missing)


Close all browsers/applications/windows/email, etc., except HijackThis and click on "fix checked".

===============================

Now let's clean up the remnants and check if there is anything else hiding around.

Update AVG Anti Spyware, per previous instructions.

===============================

Boot into Safe Mode per previous instructions

==============================

From Safe Mode run Ccleaner and AVG Anti Spyware as instructed earlier.

==============================

Boot into Normal Mode and try Panda online scan again.

==============================

Please post back a fresh HijackThis log taken after all these scans, AVG Anti Spyware report and the Panda Online scan results.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users