What the Tech logo

What the Tech? It's as easy as 1,2,3! ( Log In | Register )

Easy as 1,2,3!
Closed TopicStart new topic
> [Resolved] Trojan.Script.Iframer possible infection
stargazercece
post Oct 11 2009, 06:36 PM
Post #1


Authentic Member
**

Group: Authentic Member
Posts: 20
Joined: 14-August 09
Member No.: 87,329
Operating System: Windows Vista



Here I am once again. This time as I was heading to a website my Kaspersky popped up and said that there was a virus there - Trojan.Script.Iframer - and to cancel the page. I did but my IE is acting strange. Some scripts on the page aren't working and my add-ons will not work either. I already restarted IE 7 since you can't reinstall it on vista. On kaspersky it says that the virus threat is detected but I'm worried my machine might have still gotten it. I've done scans in normal and safe mode but nothing popped up though.

The Root Repeal is giving trouble I keep getting this:

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/11 20:27
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================

SSDT
-------------------
SYSENTER/INT2E Hooked [0x8245d8f0]!

==EOF==

Here's the DDS log:

DDS (Ver_09-06-26.01) - NTFSx86
Run by Cece at 19:09:31.45 on Sun 10/11/2009
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_16
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.1982.886 [GMT -4:00]

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Kaspersky Anti-Virus *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}

============== Running Processes ===============

D:\Windows\system32\wininit.exe
D:\Windows\system32\lsm.exe
D:\Windows\system32\svchost.exe -k DcomLaunch
D:\Windows\system32\nvvsvc.exe
D:\Windows\system32\svchost.exe -k rpcss
D:\Windows\System32\svchost.exe -k secsvcs
D:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
D:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
D:\Windows\system32\svchost.exe -k netsvcs
D:\Windows\system32\SLsvc.exe
D:\Windows\system32\svchost.exe -k LocalService
D:\Windows\system32\rundll32.exe
D:\Windows\system32\WLANExt.exe
D:\Windows\System32\spoolsv.exe
D:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
D:\Windows\system32\svchost.exe -k NetworkService
D:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
D:\Windows\system32\taskeng.exe
D:\Windows\system32\taskeng.exe
D:\Windows\system32\Dwm.exe
D:\Windows\Explorer.EXE
D:\Program Files\Windows Defender\MSASCui.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Windows\System32\rundll32.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Windows\vsnp2uvc.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
D:\Program Files\Windows Sidebar\sidebar.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Windows\system32\svchost.exe -k imgsvc
D:\Windows\System32\svchost.exe -k WerSvcGroup
D:\Windows\system32\SearchIndexer.exe
D:\Program Files\OpenOffice.org 3\program\soffice.exe
D:\Program Files\OpenOffice.org 3\program\soffice.bin
D:\Program Files\Internet Explorer\ieuser.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
D:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
D:\Windows\System32\svchost.exe -k swprv
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Windows\system32\wbem\wmiprvse.exe
D:\Windows\system32\taskeng.exe
D:\Windows\system32\SearchProtocolHost.exe
D:\Windows\system32\SearchFilterHost.exe
D:\Windows\system32\DllHost.exe
D:\Windows\system32\DllHost.exe
D:\Users\Cece_Phoenix\Downloads\dds.scr

============== Pseudo HJT Report ===============

mStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - d:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - d:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - d:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - d:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - d:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - d:\program files\wot\WOT.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - d:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
TB: {73F7F495-A325-4C52-BE48-5F97FA511E89} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - d:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - d:\program files\wot\WOT.dll
uRun: [Sidebar] d:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [swg] "d:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ehTray.exe] d:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] d:\program files\windows media player\WMPNSCFG.exe
uRun: [Skype] "d:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ISUSPM] "d:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [AVP] "d:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE d:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE d:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [TkBellExe] "d:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [snp2uvc] d:\windows\vsnp2uvc.exe
mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe"
mRun: [BlackBerryAutoUpdate] d:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [RoxWatchTray] "d:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRunOnce: [Uninstall Adobe Download Manager] "d:\windows\system32\rundll32.exe" "d:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
mRunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
StartupFolder: d:\users\cece\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - d:\program files\microsoft office\office12\ONENOTEM.EXE
uPolicies-explorer: HideSCANetwork = 0 (0x0)
uPolicies-explorer: HideSCAVolume = 0 (0x0)
mPolicies-explorer: NoAutorun = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - {73F7F495-A325-4C52-BE48-5F97FA511E89}
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - d:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - d:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/E/3/9/E39C664F-A8E3-4F69-A109-1AE9849204EE/OGAControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - d:\program files\wot\WOT.dll
Notify: klogon - d:\windows\system32\klogon.dll
AppInit_DLLs: d:\progra~1\kasper~1\kasper~2\mzvkbd3.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
d:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
d:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
d:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
d:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
d:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
d:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
d:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
d:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
d:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
d:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 klbg;Kaspersky Lab Boot Guard Driver;d:\windows\system32\drivers\klbg.sys [2008-12-15 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;d:\windows\system32\drivers\klim6.sys [2008-3-26 21008]
R3 klmouflt;Kaspersky Lab KLMOUFLT;d:\windows\system32\drivers\klmouflt.sys [2009-5-16 19472]
S2 0301941240878354mcinstcleanup;0301941240878354mcinstcleanup; [x]
S3 getPlusHelper;getPlus® Helper;d:\windows\system32\svchost.exe -k getPlusHelper [2009-3-25 21504]

=============== Created Last 30 ================

2009-10-11 15:15 0 a--sh--- d:\windows\system32\drivers\ISwift3.dat
2009-10-10 12:32 <DIR> --d----- d:\program files\JRE
2009-10-10 12:31 <DIR> --d----- d:\program files\OpenOffice.org 3
2009-10-03 01:01 195,440 -------- d:\windows\system32\MpSigStub.exe
2009-09-27 21:00 <DIR> --d----- d:\programdata\NOS
2009-09-21 19:19 <DIR> --dsh--- D:\$RECYCLE.BIN
2009-09-21 19:02 229,888 a------- d:\windows\PEV.exe
2009-09-21 19:02 161,792 a------- d:\windows\SWREG.exe
2009-09-21 19:02 98,816 a------- d:\windows\sed.exe
2009-09-20 14:58 <DIR> --d----- d:\program files\MSXML 4.0
2009-09-19 21:58 <DIR> --d----- d:\programdata\InstallShield
2009-09-19 21:57 <DIR> --d----- d:\programdata\Sonic
2009-09-19 21:51 <DIR> --d----- d:\programdata\Roxio
2009-09-19 21:51 <DIR> --d----- d:\program files\Roxio
2009-09-19 21:51 <DIR> --d----- d:\program files\common files\Sonic Shared
2009-09-19 21:45 27,136 a------- d:\windows\system32\drivers\RimSerial.sys
2009-09-19 20:29 256 a------- d:\windows\system32\pool.bin
2009-09-19 20:29 <DIR> --d----- d:\users\cece\appdata\roaming\Research In Motion
2009-09-15 21:27 <DIR> --d----- d:\programdata\Kaspersky Lab Setup Files
2009-09-15 21:27 <DIR> --d----- d:\progra~2\Kaspersky Lab Setup Files

==================== Find3M ====================

2009-10-11 18:56 56,800 a------- d:\programdata\nvModes.dat
2009-10-11 18:56 56,800 a------- d:\progra~2\nvModes.dat
2009-10-07 09:12 382,072 a------- d:\windows\system32\perfh011.dat
2009-10-07 09:12 101,350 a------- d:\windows\system32\perfc011.dat
2009-09-22 10:33 107,547 a------- d:\windows\system32\drivers\klin.dat
2009-09-22 10:33 95,259 a------- d:\windows\system32\drivers\klick.dat
2009-09-19 21:45 143,360 a------- d:\windows\inf\infstrng.dat
2009-09-19 21:45 51,200 a------- d:\windows\inf\infpub.dat
2009-09-19 21:45 86,016 a------- d:\windows\inf\infstor.dat
2009-09-15 21:45 835,616 a--sh--- d:\windows\system32\drivers\fidbox2.dat
2009-09-15 21:45 4,984 a--sh--- d:\windows\system32\drivers\fidbox2.idx
2009-09-15 21:45 4,150,304 a--sh--- d:\windows\system32\drivers\fidbox.dat
2009-09-15 21:45 34,552 a--sh--- d:\windows\system32\drivers\fidbox.idx
2009-08-28 08:39 28,672 a------- d:\windows\system32\Apphlpdm.dll
2009-08-28 08:39 173,056 a------- d:\windows\apppatch\AcXtrnal.dll
2009-08-28 08:38 2,153,984 a------- d:\windows\apppatch\AcGenral.dll
2009-08-28 08:38 541,696 a------- d:\windows\apppatch\AcLayers.dll
2009-08-28 08:38 459,776 a------- d:\windows\apppatch\AcSpecfc.dll
2009-08-28 06:15 4,240,384 a------- d:\windows\system32\GameUXLegacyGDFs.dll
2009-08-21 21:01 56 a---h--- d:\programdata\ezsidmv.dat
2009-08-21 21:01 56 a---h--- d:\progra~2\ezsidmv.dat
2009-08-14 13:07 897,608 a------- d:\windows\system32\drivers\tcpip.sys
2009-08-14 12:29 104,960 a------- d:\windows\system32\netiohlp.dll
2009-08-14 12:29 17,920 a------- d:\windows\system32\netevent.dll
2009-08-14 10:16 17,920 a------- d:\windows\system32\ROUTE.EXE
2009-08-14 10:16 9,728 a------- d:\windows\system32\TCPSVCS.EXE
2009-08-14 10:16 11,264 a------- d:\windows\system32\MRINFO.EXE
2009-08-14 10:16 27,136 a------- d:\windows\system32\NETSTAT.EXE
2009-08-14 10:16 19,968 a------- d:\windows\system32\ARP.EXE
2009-08-14 10:16 10,240 a------- d:\windows\system32\finger.exe
2009-08-14 10:16 8,704 a------- d:\windows\system32\HOSTNAME.EXE
2009-08-03 15:07 403,816 a------- d:\windows\system32\OGACheckControl.dll
2009-08-03 15:07 322,928 a------- d:\windows\system32\OGAAddin.dll
2009-08-03 15:07 230,768 a------- d:\windows\system32\OGAEXEC.exe
2009-07-31 15:23 411,368 a------- d:\windows\system32\deploytk.dll
2009-07-18 12:06 827,904 a------- d:\windows\system32\wininet.dll
2009-07-18 12:01 78,336 a------- d:\windows\system32\ieencode.dll
2009-07-18 05:46 26,624 a------- d:\windows\system32\ieUnatt.exe
2009-07-17 10:35 71,680 a------- d:\windows\system32\atl.dll
2009-07-14 09:00 313,344 a------- d:\windows\system32\wmpdxm.dll
2009-07-14 08:59 4,096 a------- d:\windows\system32\dxmasf.dll
2009-07-14 08:58 7,680 a------- d:\windows\system32\spwmp.dll
2009-07-14 06:59 8,147,456 a------- d:\windows\system32\wmploc.DLL
2009-05-05 20:04 12,978 a------- d:\users\cece\appdata\roaming\nvModes.dat
2009-03-26 03:08 665,600 a------- d:\windows\inf\drvindex.dat
2009-03-26 03:02 139,030 a------- d:\windows\inf\perflib\0411\perfi.dat
2009-03-26 03:02 139,030 a------- d:\windows\inf\perflib\0411\perfh.dat
2009-03-26 03:02 30,674 a------- d:\windows\inf\perflib\0411\perfd.dat
2009-03-26 03:02 30,674 a------- d:\windows\inf\perflib\0411\perfc.dat
2009-03-25 13:45 174 a--sh--- d:\program files\desktop.ini
2006-11-02 08:40 287,440 a------- d:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:40 287,440 a------- d:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:40 30,674 a------- d:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:40 30,674 a------- d:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a------- d:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a------- d:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a------- d:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a------- d:\windows\inf\perflib\0000\perfc.dat
2009-05-12 04:47 16,384 a--sh--- d:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-05-12 04:47 32,768 a--sh--- d:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-05-12 04:47 16,384 a--sh--- d:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat

============= FINISH: 19:10:01.16 ===============

and the attach txt is there
Attached File(s)
Attached File  Attach.txt ( 11.37K ) Number of downloads: 106
 
Go to the top of the page
 
+Quote Post
2 Pages V  < 1 2  
Start new topic
Replies (15 - 15)
ken545
post Oct 30 2009, 06:29 AM
Post #16


Forum God
Group Icon

Group: Classroom Teacher
Posts: 10,035
Joined: 3-December 04
From: Darien, Connecticut
Member No.: 19,436
Operating System: Win Xp Home SP3 Vista Home Premium SP2





Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Go to the top of the page
 
+Quote Post

2 Pages V  < 1 2
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 21st November 2009 - 05:45 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy