This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Browser Search Hijacker + Blocked AV Sites. What Malwa

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

How is your computer running?



  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
It's been running pretty well actually since early on in the process. About the point where I could log into this site again from the machine. But I haven't tried Search yet without your signal. I'm assuming now I should give it a try and will do so when I get home tonight. The one thing I still want to know about is whether the Malware that made it onto my machine could have compromised my personal info rather than just the spamming. I've tried to read up on the few names that were noted by the various apps and none seemed particularly worrisome. But the root-kit stuff was just removed without stating what it was. I purposely don't use that machine for most personal stuff like online banking or similar, but I did notice I accidentally left my 2007 Turbotax on there instead of removing it after and archiving it on CD like I normally do. (Kicking myself over that.) Containing my name, address and social security number is something of a concern if there was a way any of the malware could have lifted that file.

It's been running pretty well actually since early on in the process. About the point where I could log into this site again from the machine.


That's good to hear


But I haven't tried Search yet without your signal. I'm assuming now I should give it a try and will do so when I get home tonight.


Yeah go ahead and try a search and let me know what happens.



The one thing I still want to know about is whether the Malware that made it onto my machine could have compromised my personal info rather than just the spamming. I've tried to read up on the few names that were noted by the various apps and none seemed particularly worrisome. But the root-kit stuff was just removed without stating what it was.


Here is a list of infections that you had:

Rootkit
Trojan.Downloader.Bredolab
Trojan.Agent
Trojan/Backdoor
AdWare.Win32.Aureate.a


Rootkits and Trojans are used to steal personal information from people's computers. The thing about rootkits is, they can be on your computer and you might not even know it. What they do is replace vital system files which may then be used to hide processes and files the attacker has installed along with the presence of the rootkit itself.
RSIT logs below. BTW, I went ahad and ran a couple searches and they contained legit results.

—

Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-03-02 21:03:48
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 10 GB (11%) free of 88 GB
Total RAM: 1535 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:03:52 PM, on 3/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Downloads\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Jason Tanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.the-holocron.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1176313003984
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A876265-EA61-4452-9EFF-8E8E80FC6F69}: NameServer = 68.94.156.1,68.94.157.1
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 7031 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-01-29 145424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-02-24 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-02-24 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-01-29 145424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"=Mixer.exe /startup []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-08-11 86016]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2006-09-07 15872]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2007-11-01 582992]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2007-11-30 1164576]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-02-13 509784]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-02-24 148888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe boot []
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-11-07 21633320]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-02-25 1830128]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"=C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [2007-09-01 79408]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Red Storm Entertainment\Ghost Recon\GhostRecon.exe"="C:\Program Files\Red Storm Entertainment\Ghost Recon\GhostRecon.exe:*:Enabled:GhostRecon"
"C:\Program Files\Java\j2re1.4.2_04\bin\javaw.exe"="C:\Program Files\Java\j2re1.4.2_04\bin\javaw.exe:*:Enabled:javaw"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\GlobalSCAPE\CuteFTP\cutftp32.exe"="C:\Program Files\GlobalSCAPE\CuteFTP\cutftp32.exe:*:Enabled:Winsock FTP Client"
"C:\Program Files\Java\jre1.6.0_03\bin\javaw.exe"="C:\Program Files\Java\jre1.6.0_03\bin\javaw.exe:*:Enabled:Java™ Platform SE binary"
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"xpsptdlg.exe"="xpsptdlg.exe:*:enabled:Agent Protocol"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-03-02 21:03:48 —-D—- C:\rsit
2009-02-25 01:45:47 —-HDC—- C:\WINDOWS\$NtUninstallKB967715$
2009-02-24 00:58:39 —-SHD—- C:\RECYCLER
2009-02-24 00:46:05 —-A—- C:\WINDOWS\system32\javaws.exe
2009-02-24 00:46:05 —-A—- C:\WINDOWS\system32\javaw.exe
2009-02-24 00:46:05 —-A—- C:\WINDOWS\system32\java.exe
2009-02-24 00:45:16 —-D—- C:\Program Files\Java
2009-02-24 00:44:54 —-A—- C:\WINDOWS\system32\RENBA.tmp
2009-02-24 00:44:54 —-A—- C:\WINDOWS\system32\RENB9.tmp
2009-02-24 00:44:54 —-A—- C:\WINDOWS\system32\RENB8.tmp
2009-02-24 00:32:11 —-D—- C:\Program Files\Common Files\Adobe AIR
2009-02-24 00:30:08 —-SHD—- C:\Config.Msi
2009-02-23 08:52:19 —-D—- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-02-23 08:52:08 —-D—- C:\Program Files\SUPERAntiSpyware
2009-02-23 08:52:08 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\SUPERAntiSpyware.com
2009-02-23 08:50:57 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2009-02-20 23:28:23 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\Malwarebytes
2009-02-20 23:28:16 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2009-02-20 23:28:16 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-02-20 09:11:46 —-A—- C:\ComboFix.txt
2009-02-20 08:56:42 —-A—- C:\WINDOWS\zip.exe
2009-02-20 08:56:42 —-A—- C:\WINDOWS\VFIND.exe
2009-02-20 08:56:42 —-A—- C:\WINDOWS\SWXCACLS.exe
2009-02-20 08:56:42 —-A—- C:\WINDOWS\SWSC.exe
2009-02-20 08:56:42 —-A—- C:\WINDOWS\SWREG.exe
2009-02-20 08:56:42 —-A—- C:\WINDOWS\sed.exe
2009-02-20 08:56:42 —-A—- C:\WINDOWS\NIRCMD.exe
2009-02-20 08:56:42 —-A—- C:\WINDOWS\grep.exe
2009-02-20 08:56:42 —-A—- C:\WINDOWS\fdsv.exe
2009-02-19 00:55:41 —-D—- C:\Program Files\Trend Micro
2009-02-19 00:30:48 —-A—- C:\Boot.bak
2009-02-19 00:30:43 —-RASHD—- C:\cmdcons
2009-02-19 00:28:28 —-D—- C:\WINDOWS\ERDNT
2009-02-19 00:28:28 —-D—- C:\Qoobox
2009-02-14 14:06:59 —-D—- C:\Program Files\MSXML 4.0
2009-02-14 00:30:22 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\Mozilla
2009-02-14 00:30:10 —-D—- C:\Program Files\Mozilla Firefox
2009-02-13 23:09:21 —-A—- C:\WINDOWS\system32\lsdelete.exe
2009-02-13 22:29:07 —-DC—- C:\WINDOWS\system32\DRVSTORE
2009-02-13 22:25:02 —-HDC—- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-13 22:24:53 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-02-13 20:32:07 —-A—- C:\WINDOWS\isRS-000.tmp
2009-02-13 20:31:36 —-D—- C:\Binaries
2009-02-13 18:13:01 —-D—- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2009-02-13 18:08:02 —-D—- C:\Program Files\McAfee.com
2009-02-13 18:07:55 —-D—- C:\Program Files\Common Files\McAfee
2009-02-13 18:07:41 —-D—- C:\Program Files\McAfee
2009-02-13 17:20:19 —-D—- C:\Documents and Settings\All Users\Application Data\McAfee
2009-02-11 10:40:13 —-HDC—- C:\WINDOWS\$NtUninstallKB960715$

======List of files/folders modified in the last 1 months======

2009-03-02 21:03:49 —-D—- C:\WINDOWS\Temp
2009-03-02 21:03:33 —-D—- C:\WINDOWS\Prefetch
2009-03-02 21:02:56 —-D—- C:\Downloads
2009-03-02 20:32:02 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\Skype
2009-03-02 20:30:42 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\skypePM
2009-03-02 10:25:12 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-02-25 08:48:17 —-D—- C:\WINDOWS
2009-02-25 08:47:01 —-D—- C:\WINDOWS\system32
2009-02-25 01:45:56 —-HD—- C:\WINDOWS\inf
2009-02-25 01:45:51 —-RSHDC—- C:\WINDOWS\system32\dllcache
2009-02-25 00:25:18 —-HD—- C:\WINDOWS\$hf_mig$
2009-02-25 00:25:16 —-D—- C:\WINDOWS\system32\CatRoot2
2009-02-24 00:46:16 —-SHD—- C:\WINDOWS\Installer
2009-02-24 00:45:21 —-A—- C:\WINDOWS\system32\deploytk.dll
2009-02-24 00:45:16 —-RD—- C:\Program Files
2009-02-24 00:32:33 —-D—- C:\Program Files\Adobe
2009-02-24 00:32:11 —-D—- C:\Program Files\Common Files
2009-02-24 00:31:51 —-D—- C:\Documents and Settings\All Users\Application Data\Adobe
2009-02-24 00:31:11 —-D—- C:\Program Files\Common Files\Adobe
2009-02-24 00:31:04 —-D—- C:\WINDOWS\WinSxS
2009-02-24 00:13:19 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\AdobeUM
2009-02-21 08:52:05 —-A—- C:\WINDOWS\ntbtlog.txt
2009-02-21 08:45:54 —-A—- C:\WINDOWS\system32\advert.dll
2009-02-20 23:52:57 —-D—- C:\WINDOWS\system32\drivers
2009-02-20 09:04:20 —-A—- C:\WINDOWS\system.ini
2009-02-20 09:01:00 —-D—- C:\WINDOWS\system32\config
2009-02-20 08:59:50 —-D—- C:\WINDOWS\AppPatch
2009-02-19 00:30:48 —-RASH—- C:\boot.ini
2009-02-18 09:53:45 —-D—- C:\My Shared Folder
2009-02-18 09:53:45 —-D—- C:\Incomplete
2009-02-15 19:40:54 —-SD—- C:\WINDOWS\Downloaded Program Files
2009-02-13 23:58:39 —-A—- C:\WINDOWS\wininit.ini
2009-02-13 23:13:52 —-D—- C:\WINDOWS\PrimoPDF
2009-02-13 22:29:04 —-SD—- C:\WINDOWS\Tasks
2009-02-13 22:24:53 —-D—- C:\Program Files\Lavasoft
2009-02-13 20:32:08 —-A—- C:\WINDOWS\win.ini
2009-02-13 01:52:52 —-D—- C:\WINDOWS\SoftwareDistribution
2009-02-11 20:56:18 —-A—- C:\WINDOWS\system32\MRT.exe
2009-02-11 10:40:18 —-A—- C:\WINDOWS\imsins.BAK
2009-02-03 00:31:20 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\ArcSoft
2009-02-03 00:30:53 —-HD—- C:\Program Files\InstallShield Installation Information
2009-02-03 00:30:53 —-D—- C:\Program Files\ArcSoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver; \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys []
R1 AvgAsCln;AVG Anti-Spyware Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys [2006-09-05 3968]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2007-11-22 201320]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2007-07-13 113952]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [1999-09-13 72704]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2001-10-30 280782]
R3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2001-08-17 117760]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2004-05-27 19968]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2007-11-22 79304]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2007-11-22 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2007-12-02 40488]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2003-03-31 12160]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 catchme;catchme; \??\C:\Combo-Fix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2007-11-22 33832]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 P1120VID;Creative WebCam NX Ultra; C:\WINDOWS\System32\DRIVERS\P1120Vid.sys [2003-09-18 759050]
S3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1); C:\WINDOWS\system32\DRIVERS\CamDrL20.sys [2004-05-21 245760]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard; C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe [2007-09-01 312880]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-02-24 152984]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-02-13 950096]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2009-01-23 203280]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-01-09 767976]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-01-25 2458128]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2007-08-15 359248]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2007-07-24 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2007-07-18 856864]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2007-12-05 695624]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2007-11-07 378184]

—————–EOF—————–
info.txt logfile of random's system information tool 1.05 2009-03-02 21:03:56

======Uninstall list======

–>C:\PROGRA~1\GLOBAL~1\CuteFTP\UNWISE32.EXE C:\PROGRA~1\GLOBAL~1\CuteFTP\CuteHTML\INSTALL2.LOG
–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–>C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\After Effects 4.1\Uninst.isu" -c"C:\Program Files\Adobe\After Effects 4.1\Uninst.dll"
–>C:\WINDOWS\System32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
–>C:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CA9EC1C6-3B51-11D6-B1A9-BCD2747AA951}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D43F13A1-1E39-4BD4-9682-DF889FE75421}\setup.exe" -l0x9
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Ad-Aware SE Personal–>C:\PROGRA~1\Lavasoft\AD-AWA~2\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~2\INSTALL.LOG
Ad-Aware–>"C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware–>C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
Adobe After Effects 4.1–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Adobe\After Effects 4.1\Uninst.isu"
Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop Album 2.0 Starter Edition–>MsiExec.exe /I{11B569C2-4BF6-4ED0-9D17-A4273943CB24}
Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Adobe Shockwave Player 11–>C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
ArcSoft PhotoStudio 5.5–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9DCCCCD2-F531-41D1-BF2F-B577FBD9694C}\setup.exe" -l0x9
ArcSoft ShowBiz DVD 2–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CE636486-7E13-4051-9067-AFC4E1B8F54E}\Setup.exe" -l0x9
Audacity 1.2.1–>"C:\Program Files\Audacity\unins000.exe"
AVG Anti-Spyware 7.5–>C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
Axogon Composer 0.93–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Axogon\Composer\Uninst.isu"
Creative PC-CAM Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D43F13A1-1E39-4BD4-9682-DF889FE75421}\setup.exe" -l0x9 /remove
Creative WebCam Monitor–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CA9EC1C6-3B51-11D6-B1A9-BCD2747AA951}\setup.exe" -l0x9 /remove
Creative WebCam NX Ultra Driver (1.00.06.0919)–>C:\WINDOWS\CtDrvIns.exe -uninstall -script Pd1120.uns -unsext NT -plugin P1120Pin.dll -pluginres P1120Pin.crl
Creative WebCam NX Ultra User's Guide (English)–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Creative\Creative WebCam NX Ultra\Creative WebCam NX Ultra User's Guide\English\CTManual.isu"
CuteFTP–>C:\PROGRA~1\GLOBAL~1\CuteFTP\UNWISE32.EXE C:\PROGRA~1\GLOBAL~1\CuteFTP\INSTALL.LOG
CutePDF Writer 2.6–>C:\WINDOWS\system32\uninscpw.exe C:\Program Files\
Diablo II–>C:\WINDOWS\DIIUnin.exe C:\WINDOWS\DIIUnin.dat
DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
EPSON CardMonitor–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{109D28C7-FB38-483A-9C91-001CB59E2699}\Setup.exe" -l0x9 uninst
EPSON PhotoStarter3.0–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5983C895-DDA4-45D9-A8D1-877D5DE7693E}\Setup.exe" uninst
EPSON Print CD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}\Setup.exe" -l0x9 -SYSTEM
EPSON Printer Software–>C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Scan–>C:\Program Files\epson\escndv\setup\setup.exe /r
EPSON SPR300 Reference Guide–>C:\Program Files\epson\guide\spr300_e\uninstall.exe
EPSON TWAIN 5–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A3EABC0-CA06-11D4-BF77-00104B130C19}\Setup.exe" UNINSTALL
Football Pro '98–>C:\WINDOWS\IsUninst.exe -fC:\SIERRA\FbPro98\Uninst.isu
Ghost Recon–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D89EF3B3-6F17-4665-B7A9-A4235A6DC787}\Setup.exe"
Google Video Uploader–>"C:\Program Files\Google Video\Uninstall.exe"
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP DVD Movie Writer Capture Device–>MsiExec.exe /I{CF77173D-DF44-4CF2-907C-3A99EAFDF6E7}
HP DVD Movie Writer–>"C:\Program Files\HP DVD\Support\Uninstall.exe" /UNINSTALL
HP Software Update–>MsiExec.exe /X{6FA269F8-38CB-4DF7-AA0D-36E3CE789485}
Java™ 6 Update 12–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
jetAudio–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\Setup.exe" -l0x9
LimeWire 4.18.8–>"C:\Program Files\LimeWire\uninstall.exe"
Logitech® Camera Driver–>"C:\Program Files\Common Files\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
Macromedia Shockwave Player–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Magpie–>C:\WINDOWS\IsUninst.exe -fC:\Magpie\Uninst.isu
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter–>C:\Program Files\McAfee\MSC\mcuninst.exe
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Data Access Components KB870669–>C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft DirectX Transform optional components–>RUNDLL32.EXE ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\DXTXTRA.INF,UNINSTALL.NT,12
Microsoft Office 2000 Premium–>MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Moyager 1.3.4–>"C:\Program Files\Moyager-1.3.4\unins000.exe"
Mozilla Firefox (3.0.6)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN Music Assistant–>rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,Uninstall
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 and SOAP Toolkit 3.0–>MsiExec.exe /I{32343DB6-9A52-40C9-87E4-5E7C79791C87}
NVIDIA Drivers–>C:\WINDOWS\system32\nvudisp.exe UninstallGUI
PCI Audio Applications–>C:\Program Files\PCI Audio Applications\Bin\Uninstall.exe
PCI Audio Driver–>cmuninst.exe
Pdf995–>c:\pdf995\setup.exe uninstall
PdfEdit995–>c:\pdf995\res\utilities\thinsetup.exe - uninstall
Polaroid PDC 2300Z Camera Driver 1.0.0.2.1E–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECBE1604-4858-11D5-8C45-00A024AA4B82}\Setup.exe"
PowerDVD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
PrimoPDF Redistribution Package–>MsiExec.exe /I{885744A4-1A01-44B0-858A-0AE6738CBCF7}
PrimoPDF–>"C:\WINDOWS\PrimoPDF\uninstall.exe" "/U:C:\Program Files\activePDF\PrimoPDF\Uninstall\uninstall.xml"
QuickTime–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083} /l1033
RealPlayer–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
RealProducer Basic 10–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B8C0986-647E-40D5-8C36-C67E5A606EBB}\Setup.exe" -l0x9 RunSemiSilent
RecordNow!–>MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Rhapsody Player Engine–>MsiExec.exe /I{21F6B15F-1198-4FA2-8F31-5A24C1FBE144}
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950759)–>"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)–>"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)–>"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)–>"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956390)–>"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958215)–>"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)–>"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960714)–>"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)–>"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Sentinel System Driver–>C:\WINDOWS\SYSTEM32\RNBOSENT\SETUPX86.EXE /U /q
Skype™ 3.8–>MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Sonic Update Manager–>MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
SUPER © Version 2006.19 (FIX)–>C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
SUPERAntiSpyware Free Edition–>MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Trillian–>C:\Program Files\Trillian\trillian.exe /uninstall
TurboTax Deluxe 2007–>C:\Program Files\TurboTax\Deluxe 2007\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2007\Uninstall.log" -NoGui
Unlocker 1.8.5–>C:\Program Files\Unlocker\uninst.exe
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)–>"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
VideoMach 2.7.2–>"C:\Program Files\VideoMach-2.7.2\unins000.exe"
Visual C++ 2008 x86 Runtime - (v9.0.30729)–>MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01–>C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Windows Media Format Runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe
Xfire (remove only)–>"C:\Program Files\Xfire\uninst.exe"
Yahoo! Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

======Security center information======

AV: McAfee VirusScan
FW: McAfee Personal Firewall

System event log

Computer Name: BURKE
Event Code: 7036
Message: The Windows Installer service entered the stopped state.

Record Number: 44338
Source Name: Service Control Manager
Time Written: 20090213010652.000000-480
Event Type: information
User:

Computer Name: BURKE
Event Code: 4226
Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Record Number: 44337
Source Name: Tcpip
Time Written: 20090213010146.000000-480
Event Type: warning
User:

Computer Name: BURKE
Event Code: 64002
Message: File replacement was attempted on the protected system file svchost.exe.
This file was restored to the original version to maintain system stability.
The file version of the system file is 5.1.2600.5512.

Record Number: 44336
Source Name: Windows File Protection
Time Written: 20090213005657.000000-480
Event Type: information
User:

Computer Name: BURKE
Event Code: 7036
Message: The Computer Browser service entered the running state.

Record Number: 44335
Source Name: Service Control Manager
Time Written: 20090213005652.000000-480
Event Type: information
User:

Computer Name: BURKE
Event Code: 7035
Message: The Computer Browser service was successfully sent a start control.

Record Number: 44334
Source Name: Service Control Manager
Time Written: 20090213005652.000000-480
Event Type: information
User: NT AUTHORITY\SYSTEM

Application event log

Computer Name: BURKE
Event Code: 11728
Message: Product: QuickTime – Configuration completed successfully.

Record Number: 5
Source Name: MsiInstaller
Time Written: 20051216101025.000000-480
Event Type: information
User: BURKE\Jason Tanner

Computer Name: BURKE
Event Code: 11707
Message: Product: QuickTime – Installation operation completed successfully.

Record Number: 4
Source Name: MsiInstaller
Time Written: 20051216101015.000000-480
Event Type: information
User: BURKE\Jason Tanner

Computer Name: BURKE
Event Code: 11707
Message: Product: QuickTime – Installation operation completed successfully.

Record Number: 3
Source Name: MsiInstaller
Time Written: 20051216100938.000000-480
Event Type: information
User: BURKE\Jason Tanner

Computer Name: BURKE
Event Code: 0
Message:
Record Number: 2
Source Name: IDriverT
Time Written: 20051216100444.000000-480
Event Type: information
User:

Computer Name: BURKE
Event Code: 11707
Message: Product: InstallScriptMSIEngine – Installation operation completed successfully.

Record Number: 1
Source Name: MsiInstaller
Time Written: 20051216100440.000000-480
Event Type: information
User: BURKE\Jason Tanner

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Real\RealProducer Basic 10;C:\Program Files\QuickTime\QTSystem
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=C:\Program Files\Java\j2re1.4.2_04\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\j2re1.4.2_04\lib\ext\QTJava.zip

—————–EOF—————–
Step #1

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):


LimeWire 4.18.8


Then Reboot


Step #2

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Here's the log:


——————–\\ Lop S&D; 4.2.5-0 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 2.40GHz )
BIOS : Award Medallion BIOS v6.0
USER : Jason Tanner ( Administrator )
BOOT : Normal boot
Antivirus : McAfee VirusScan (Not Activated)
Firewall : McAfee Personal Firewall (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:86 Go (Free:9 Go)
D:\ (CD or DVD)
E:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Thu 03/05/2009| 9:53 )

——————–\\ Listing folders in APPLIC~1

[02/13/2009|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {83C91755-2546-441D-AC40-9A6B4B860800}
[02/24/2009|12:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[12/16/2005|10:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[05/30/2004|07:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[09/01/2007|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Grisoft
[03/31/2007|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[12/23/2006|01:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Kazaa
[02/13/2009|10:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[02/20/2009|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[02/13/2009|06:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee
[12/13/2005|12:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[12/03/2004|12:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[02/19/2008|08:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ pdf995
[05/26/2004|08:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[02/13/2009|06:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SiteAdvisor
[01/19/2009|10:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Skype
[02/23/2009|08:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com
[04/11/2007|09:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[03/03/2009|05:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo!
[03/04/2009|08:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion

[05/21/2006|06:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[09/19/2005|12:08] C:\DOCUME~1\JASONT~1\APPLIC~1\ .bittorrent
[01/05/2009|09:37] C:\DOCUME~1\JASONT~1\APPLIC~1\ Adobe
[07/03/2006|03:57] C:\DOCUME~1\JASONT~1\APPLIC~1\ AdobeAUM
[02/24/2009|12:13] C:\DOCUME~1\JASONT~1\APPLIC~1\ AdobeUM
[12/22/2005|10:37] C:\DOCUME~1\JASONT~1\APPLIC~1\ Apple Computer
[02/03/2009|12:31] C:\DOCUME~1\JASONT~1\APPLIC~1\ ArcSoft
[04/24/2005|11:10] C:\DOCUME~1\JASONT~1\APPLIC~1\ Canon
[05/30/2004|12:08] C:\DOCUME~1\JASONT~1\APPLIC~1\ COWON
[06/18/2004|11:30] C:\DOCUME~1\JASONT~1\APPLIC~1\ Creative
[11/10/2008|09:53] C:\DOCUME~1\JASONT~1\APPLIC~1\ ePaperPress
[07/03/2005|09:43] C:\DOCUME~1\JASONT~1\APPLIC~1\ EPSON
[12/13/2005|12:30] C:\DOCUME~1\JASONT~1\APPLIC~1\ Explorer
[05/31/2004|10:15] C:\DOCUME~1\JASONT~1\APPLIC~1\ Help
[05/21/2006|06:41] C:\DOCUME~1\JASONT~1\APPLIC~1\ Identities
[03/31/2007|10:37] C:\DOCUME~1\JASONT~1\APPLIC~1\ Intuit
[12/23/2005|11:44] C:\DOCUME~1\JASONT~1\APPLIC~1\ Juniper Networks
[05/31/2004|12:04] C:\DOCUME~1\JASONT~1\APPLIC~1\ Kazaa Lite
[12/13/2005|12:44] C:\DOCUME~1\JASONT~1\APPLIC~1\ Lavasoft
[05/25/2004|09:08] C:\DOCUME~1\JASONT~1\APPLIC~1\ Leadertech
[02/18/2006|05:25] C:\DOCUME~1\JASONT~1\APPLIC~1\ LucasArts
[07/05/2004|06:58] C:\DOCUME~1\JASONT~1\APPLIC~1\ Macromedia
[02/20/2009|11:28] C:\DOCUME~1\JASONT~1\APPLIC~1\ Malwarebytes
[11/17/2008|09:44] C:\DOCUME~1\JASONT~1\APPLIC~1\ Microsoft
[08/25/2006|09:10] C:\DOCUME~1\JASONT~1\APPLIC~1\ Microsoft Web Folders
[05/16/2008|09:08] C:\DOCUME~1\JASONT~1\APPLIC~1\ Move Networks
[02/14/2009|12:30] C:\DOCUME~1\JASONT~1\APPLIC~1\ Mozilla
[07/05/2005|11:23] C:\DOCUME~1\JASONT~1\APPLIC~1\ Musicmatch
[08/27/2006|07:27] C:\DOCUME~1\JASONT~1\APPLIC~1\ pdf995
[03/19/2006|12:01] C:\DOCUME~1\JASONT~1\APPLIC~1\ Real
[03/10/2007|12:37] C:\DOCUME~1\JASONT~1\APPLIC~1\ SecuROM
[03/05/2009|09:52] C:\DOCUME~1\JASONT~1\APPLIC~1\ Skype
[03/05/2009|09:25] C:\DOCUME~1\JASONT~1\APPLIC~1\ skypePM
[05/25/2004|09:07] C:\DOCUME~1\JASONT~1\APPLIC~1\ Sonic
[06/03/2004|12:27] C:\DOCUME~1\JASONT~1\APPLIC~1\ Sun
[02/23/2009|08:52] C:\DOCUME~1\JASONT~1\APPLIC~1\ SUPERAntiSpyware.com
[10/05/2006|02:17] C:\DOCUME~1\JASONT~1\APPLIC~1\ Talkback
[08/15/2007|10:07] C:\DOCUME~1\JASONT~1\APPLIC~1\ U3
[02/18/2006|03:21] C:\DOCUME~1\JASONT~1\APPLIC~1\ Xfire
[03/03/2009|05:41] C:\DOCUME~1\JASONT~1\APPLIC~1\ Yahoo!

[05/21/2006|06:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[02/23/2009|09:21] C:\DOCUME~1\LOCALS~1\APPLIC~1\ SACore

[05/21/2006|06:37] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[03/02/2009 10:29 PM][–a——] C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[02/13/2009 06:08 PM][–a——] C:\WINDOWS\tasks\McDefragTask.job
[02/13/2009 06:08 PM][–a——] C:\WINDOWS\tasks\McQcTask.job
[03/05/2009 09:24 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[03/31/2003 04:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[07/01/2006|08:37] C:\Program Files\ Acro Software
[02/26/2008|09:53] C:\Program Files\ activePDF
[02/24/2009|12:32] C:\Program Files\ Adobe
[02/03/2009|12:30] C:\Program Files\ ArcSoft
[07/17/2004|06:39] C:\Program Files\ Audacity
[11/26/2006|05:54] C:\Program Files\ AviSynth 2.5
[07/22/2004|11:39] C:\Program Files\ Axogon
[05/23/2004|09:48] C:\Program Files\ C-Media
[02/24/2009|12:32] C:\Program Files\ Common Files
[05/21/2006|06:31] C:\Program Files\ ComPlus Applications
[05/31/2004|12:58] C:\Program Files\ Creative
[05/30/2004|07:08] C:\Program Files\ CyberLink
[03/30/2007|09:15] C:\Program Files\ Diablo II
[05/26/2004|08:13] C:\Program Files\ DivX
[07/17/2004|11:19] C:\Program Files\ EPSON
[11/23/2005|12:32] C:\Program Files\ EPSON Print CD
[11/26/2006|05:54] C:\Program Files\ eRightSoft
[02/13/2005|10:20] C:\Program Files\ GlobalSCAPE
[12/09/2006|09:38] C:\Program Files\ Google Video
[07/01/2006|08:40] C:\Program Files\ GPLGS
[04/11/2007|12:56] C:\Program Files\ Grisoft
[05/30/2004|07:09] C:\Program Files\ Hewlett-Packard
[05/30/2004|07:08] C:\Program Files\ HP DVD
[02/03/2009|12:30] C:\Program Files\ InstallShield Installation Information
[09/13/2008|08:37] C:\Program Files\ Internet Explorer
[02/24/2009|12:45] C:\Program Files\ Java
[05/30/2004|12:13] C:\Program Files\ JetAudio
[02/21/2005|06:22] C:\Program Files\ KMZ Player
[02/13/2009|10:24] C:\Program Files\ Lavasoft
[03/12/2005|07:30] C:\Program Files\ Logitech
[02/18/2006|03:13] C:\Program Files\ LucasArts
[02/20/2009|11:28] C:\Program Files\ Malwarebytes' Anti-Malware
[02/16/2009|12:01] C:\Program Files\ McAfee
[02/13/2009|06:08] C:\Program Files\ McAfee.com
[09/13/2008|08:37] C:\Program Files\ Messenger
[08/25/2006|09:10] C:\Program Files\ microsoft frontpage
[08/25/2006|09:10] C:\Program Files\ Microsoft Office
[08/25/2006|09:11] C:\Program Files\ Microsoft Visual Studio
[09/13/2008|08:28] C:\Program Files\ Movie Maker
[07/24/2004|03:58] C:\Program Files\ Moyager-1.3.4
[03/05/2009|12:42] C:\Program Files\ Mozilla Firefox
[05/21/2006|06:30] C:\Program Files\ MSN
[05/21/2006|06:30] C:\Program Files\ MSN Gaming Zone
[10/05/2006|08:01] C:\Program Files\ MsnMusic
[08/25/2006|09:03] C:\Program Files\ MSOffice
[02/14/2009|02:06] C:\Program Files\ MSXML 4.0
[08/25/2006|08:16] C:\Program Files\ Musicmatch
[09/13/2008|08:25] C:\Program Files\ NetMeeting
[05/21/2006|06:33] C:\Program Files\ Online Services
[09/13/2008|08:24] C:\Program Files\ Outlook Express
[05/23/2004|09:47] C:\Program Files\ PCI Audio Applications
[05/30/2004|07:08] C:\Program Files\ PowerDVD
[07/31/2004|09:42] C:\Program Files\ Program Files
[04/03/2007|09:58] C:\Program Files\ QuickTime
[07/10/2004|10:52] C:\Program Files\ Real
[05/25/2004|09:07] C:\Program Files\ RecordNow!
[07/05/2004|01:32] C:\Program Files\ Red Storm Entertainment
[05/23/2008|10:27] C:\Program Files\ Sierra On-Line
[01/19/2009|10:53] C:\Program Files\ Skype
[07/12/2004|03:00] C:\Program Files\ Sma
[05/25/2004|09:06] C:\Program Files\ Sonic
[02/25/2009|12:24] C:\Program Files\ SUPERAntiSpyware
[02/25/2007|10:49] C:\Program Files\ THQ
[02/19/2009|12:55] C:\Program Files\ Trend Micro
[04/11/2008|05:33] C:\Program Files\ Trillian
[03/09/2008|10:56] C:\Program Files\ TurboTax
[05/23/2004|06:47] C:\Program Files\ Uninstall Information
[04/04/2007|01:34] C:\Program Files\ Unlocker
[11/18/2004|12:13] C:\Program Files\ Valve
[06/18/2004|11:01] C:\Program Files\ VideoMach-2.7.2
[09/13/2008|08:24] C:\Program Files\ Windows Media Player
[09/13/2008|08:24] C:\Program Files\ Windows NT
[08/13/2004|09:13] C:\Program Files\ WindowsUpdate
[11/23/2005|06:04] C:\Program Files\ WinRAR
[05/21/2006|06:34] C:\Program Files\ xerox
[02/18/2006|03:12] C:\Program Files\ Xfire
[03/03/2009|05:41] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[02/24/2009|12:31] C:\Program Files\Common Files\ Adobe
[02/24/2009|12:32] C:\Program Files\Common Files\ Adobe AIR
[11/22/2004|09:32] C:\Program Files\Common Files\ ArcSoft
[08/25/2006|09:11] C:\Program Files\Common Files\ Designer
[12/16/2005|10:04] C:\Program Files\Common Files\ InstallShield
[03/31/2007|10:35] C:\Program Files\Common Files\ Intuit
[06/03/2004|12:25] C:\Program Files\Common Files\ Java
[03/12/2005|07:30] C:\Program Files\Common Files\ Logitech
[02/13/2009|06:08] C:\Program Files\Common Files\ McAfee
[08/25/2006|09:11] C:\Program Files\Common Files\ Microsoft Shared
[05/21/2006|06:32] C:\Program Files\Common Files\ MSSoap
[05/21/2006|11:21] C:\Program Files\Common Files\ ODBC
[06/16/2004|07:28] C:\Program Files\Common Files\ Real
[05/21/2006|06:32] C:\Program Files\Common Files\ Services
[01/19/2009|10:53] C:\Program Files\Common Files\ Skype
[05/25/2004|09:07] C:\Program Files\Common Files\ Sonic
[05/21/2006|11:21] C:\Program Files\Common Files\ SpeechEngines
[05/25/2004|09:07] C:\Program Files\Common Files\ SureThing Shared
[09/13/2008|08:24] C:\Program Files\Common Files\ System
[02/23/2009|08:50] C:\Program Files\Common Files\ Wise Installation Wizard
[06/16/2004|07:28] C:\Program Files\Common Files\ xing shared

——————–\\ Process

( 32 Processes )

iexplore.exe ~ [PID:464]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\JASONT~1\Cookies\jason tanner@advertising[2].txt
C:\DOCUME~1\JASONT~1\Cookies\jason [removed][2].txt

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-05 09:54:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections


No other infections found !

[F:31][D:3]-> C:\DOCUME~1\JASONT~1\LOCALS~1\Temp
[F:145][D:0]-> C:\DOCUME~1\JASONT~1\Cookies
[F:7166][D:12]-> C:\DOCUME~1\JASONT~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Thu 03/05/2009| 9:56 - Option : [1]

——————–\\ Scan completed at 9:56:19
Restart Lop S&D

This time choose Option 3 (Fix - Hosts)
Don't close the window during suppression!
Post the log which is created: (%SystemDrive%\lopR.txt)
New Log:


——————–\\ Lop S&D; 4.2.5-0 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 2.40GHz )
BIOS : Award Medallion BIOS v6.0
USER : Jason Tanner ( Administrator )
BOOT : Normal boot
Antivirus : McAfee VirusScan (Not Activated)
Firewall : McAfee Personal Firewall (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:86 Go (Free:9 Go)
D:\ (CD or DVD)
E:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [3] ( Fri 03/06/2009|22:53 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX

Deleted! - C:\DOCUME~1\JASONT~1\Cookies\jason [removed][2].txt

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


——————–\\ Listing folders in APPLIC~1

[02/13/2009|10:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {83C91755-2546-441D-AC40-9A6B4B860800}
[02/24/2009|12:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[12/16/2005|10:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[05/30/2004|07:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[09/01/2007|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Grisoft
[03/31/2007|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[12/23/2006|01:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Kazaa
[02/13/2009|10:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[02/20/2009|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[02/13/2009|06:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee
[12/13/2005|12:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[12/03/2004|12:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[02/19/2008|08:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ pdf995
[05/26/2004|08:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[02/13/2009|06:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SiteAdvisor
[01/19/2009|10:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Skype
[02/23/2009|08:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com
[04/11/2007|09:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[03/03/2009|05:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo!
[03/04/2009|08:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion

[05/21/2006|06:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[09/19/2005|12:08] C:\DOCUME~1\JASONT~1\APPLIC~1\ .bittorrent
[01/05/2009|09:37] C:\DOCUME~1\JASONT~1\APPLIC~1\ Adobe
[07/03/2006|03:57] C:\DOCUME~1\JASONT~1\APPLIC~1\ AdobeAUM
[02/24/2009|12:13] C:\DOCUME~1\JASONT~1\APPLIC~1\ AdobeUM
[12/22/2005|10:37] C:\DOCUME~1\JASONT~1\APPLIC~1\ Apple Computer
[02/03/2009|12:31] C:\DOCUME~1\JASONT~1\APPLIC~1\ ArcSoft
[04/24/2005|11:10] C:\DOCUME~1\JASONT~1\APPLIC~1\ Canon
[05/30/2004|12:08] C:\DOCUME~1\JASONT~1\APPLIC~1\ COWON
[06/18/2004|11:30] C:\DOCUME~1\JASONT~1\APPLIC~1\ Creative
[11/10/2008|09:53] C:\DOCUME~1\JASONT~1\APPLIC~1\ ePaperPress
[07/03/2005|09:43] C:\DOCUME~1\JASONT~1\APPLIC~1\ EPSON
[12/13/2005|12:30] C:\DOCUME~1\JASONT~1\APPLIC~1\ Explorer
[05/31/2004|10:15] C:\DOCUME~1\JASONT~1\APPLIC~1\ Help
[05/21/2006|06:41] C:\DOCUME~1\JASONT~1\APPLIC~1\ Identities
[03/31/2007|10:37] C:\DOCUME~1\JASONT~1\APPLIC~1\ Intuit
[12/23/2005|11:44] C:\DOCUME~1\JASONT~1\APPLIC~1\ Juniper Networks
[05/31/2004|12:04] C:\DOCUME~1\JASONT~1\APPLIC~1\ Kazaa Lite
[12/13/2005|12:44] C:\DOCUME~1\JASONT~1\APPLIC~1\ Lavasoft
[05/25/2004|09:08] C:\DOCUME~1\JASONT~1\APPLIC~1\ Leadertech
[02/18/2006|05:25] C:\DOCUME~1\JASONT~1\APPLIC~1\ LucasArts
[07/05/2004|06:58] C:\DOCUME~1\JASONT~1\APPLIC~1\ Macromedia
[02/20/2009|11:28] C:\DOCUME~1\JASONT~1\APPLIC~1\ Malwarebytes
[11/17/2008|09:44] C:\DOCUME~1\JASONT~1\APPLIC~1\ Microsoft
[08/25/2006|09:10] C:\DOCUME~1\JASONT~1\APPLIC~1\ Microsoft Web Folders
[05/16/2008|09:08] C:\DOCUME~1\JASONT~1\APPLIC~1\ Move Networks
[02/14/2009|12:30] C:\DOCUME~1\JASONT~1\APPLIC~1\ Mozilla
[07/05/2005|11:23] C:\DOCUME~1\JASONT~1\APPLIC~1\ Musicmatch
[08/27/2006|07:27] C:\DOCUME~1\JASONT~1\APPLIC~1\ pdf995
[03/19/2006|12:01] C:\DOCUME~1\JASONT~1\APPLIC~1\ Real
[03/10/2007|12:37] C:\DOCUME~1\JASONT~1\APPLIC~1\ SecuROM
[03/06/2009|10:50] C:\DOCUME~1\JASONT~1\APPLIC~1\ Skype
[03/06/2009|10:42] C:\DOCUME~1\JASONT~1\APPLIC~1\ skypePM
[05/25/2004|09:07] C:\DOCUME~1\JASONT~1\APPLIC~1\ Sonic
[06/03/2004|12:27] C:\DOCUME~1\JASONT~1\APPLIC~1\ Sun
[02/23/2009|08:52] C:\DOCUME~1\JASONT~1\APPLIC~1\ SUPERAntiSpyware.com
[10/05/2006|02:17] C:\DOCUME~1\JASONT~1\APPLIC~1\ Talkback
[08/15/2007|10:07] C:\DOCUME~1\JASONT~1\APPLIC~1\ U3
[02/18/2006|03:21] C:\DOCUME~1\JASONT~1\APPLIC~1\ Xfire
[03/03/2009|05:41] C:\DOCUME~1\JASONT~1\APPLIC~1\ Yahoo!

[05/21/2006|06:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[02/23/2009|09:21] C:\DOCUME~1\LOCALS~1\APPLIC~1\ SACore

[05/21/2006|06:37] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[03/02/2009 10:29 PM][–a——] C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[02/13/2009 06:08 PM][–a——] C:\WINDOWS\tasks\McDefragTask.job
[02/13/2009 06:08 PM][–a——] C:\WINDOWS\tasks\McQcTask.job
[03/06/2009 10:41 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[03/31/2003 04:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[07/01/2006|08:37] C:\Program Files\ Acro Software
[02/26/2008|09:53] C:\Program Files\ activePDF
[02/24/2009|12:32] C:\Program Files\ Adobe
[02/03/2009|12:30] C:\Program Files\ ArcSoft
[07/17/2004|06:39] C:\Program Files\ Audacity
[11/26/2006|05:54] C:\Program Files\ AviSynth 2.5
[07/22/2004|11:39] C:\Program Files\ Axogon
[05/23/2004|09:48] C:\Program Files\ C-Media
[02/24/2009|12:32] C:\Program Files\ Common Files
[05/21/2006|06:31] C:\Program Files\ ComPlus Applications
[05/31/2004|12:58] C:\Program Files\ Creative
[05/30/2004|07:08] C:\Program Files\ CyberLink
[03/30/2007|09:15] C:\Program Files\ Diablo II
[05/26/2004|08:13] C:\Program Files\ DivX
[07/17/2004|11:19] C:\Program Files\ EPSON
[11/23/2005|12:32] C:\Program Files\ EPSON Print CD
[11/26/2006|05:54] C:\Program Files\ eRightSoft
[02/13/2005|10:20] C:\Program Files\ GlobalSCAPE
[12/09/2006|09:38] C:\Program Files\ Google Video
[07/01/2006|08:40] C:\Program Files\ GPLGS
[04/11/2007|12:56] C:\Program Files\ Grisoft
[05/30/2004|07:09] C:\Program Files\ Hewlett-Packard
[05/30/2004|07:08] C:\Program Files\ HP DVD
[02/03/2009|12:30] C:\Program Files\ InstallShield Installation Information
[09/13/2008|08:37] C:\Program Files\ Internet Explorer
[02/24/2009|12:45] C:\Program Files\ Java
[05/30/2004|12:13] C:\Program Files\ JetAudio
[02/21/2005|06:22] C:\Program Files\ KMZ Player
[02/13/2009|10:24] C:\Program Files\ Lavasoft
[03/12/2005|07:30] C:\Program Files\ Logitech
[02/18/2006|03:13] C:\Program Files\ LucasArts
[02/20/2009|11:28] C:\Program Files\ Malwarebytes' Anti-Malware
[02/16/2009|12:01] C:\Program Files\ McAfee
[02/13/2009|06:08] C:\Program Files\ McAfee.com
[09/13/2008|08:37] C:\Program Files\ Messenger
[08/25/2006|09:10] C:\Program Files\ microsoft frontpage
[08/25/2006|09:10] C:\Program Files\ Microsoft Office
[08/25/2006|09:11] C:\Program Files\ Microsoft Visual Studio
[09/13/2008|08:28] C:\Program Files\ Movie Maker
[07/24/2004|03:58] C:\Program Files\ Moyager-1.3.4
[03/06/2009|08:20] C:\Program Files\ Mozilla Firefox
[05/21/2006|06:30] C:\Program Files\ MSN
[05/21/2006|06:30] C:\Program Files\ MSN Gaming Zone
[10/05/2006|08:01] C:\Program Files\ MsnMusic
[08/25/2006|09:03] C:\Program Files\ MSOffice
[02/14/2009|02:06] C:\Program Files\ MSXML 4.0
[08/25/2006|08:16] C:\Program Files\ Musicmatch
[09/13/2008|08:25] C:\Program Files\ NetMeeting
[05/21/2006|06:33] C:\Program Files\ Online Services
[09/13/2008|08:24] C:\Program Files\ Outlook Express
[05/23/2004|09:47] C:\Program Files\ PCI Audio Applications
[05/30/2004|07:08] C:\Program Files\ PowerDVD
[07/31/2004|09:42] C:\Program Files\ Program Files
[04/03/2007|09:58] C:\Program Files\ QuickTime
[07/10/2004|10:52] C:\Program Files\ Real
[05/25/2004|09:07] C:\Program Files\ RecordNow!
[07/05/2004|01:32] C:\Program Files\ Red Storm Entertainment
[05/23/2008|10:27] C:\Program Files\ Sierra On-Line
[01/19/2009|10:53] C:\Program Files\ Skype
[07/12/2004|03:00] C:\Program Files\ Sma
[05/25/2004|09:06] C:\Program Files\ Sonic
[02/25/2009|12:24] C:\Program Files\ SUPERAntiSpyware
[02/25/2007|10:49] C:\Program Files\ THQ
[02/19/2009|12:55] C:\Program Files\ Trend Micro
[04/11/2008|05:33] C:\Program Files\ Trillian
[03/09/2008|10:56] C:\Program Files\ TurboTax
[05/23/2004|06:47] C:\Program Files\ Uninstall Information
[04/04/2007|01:34] C:\Program Files\ Unlocker
[11/18/2004|12:13] C:\Program Files\ Valve
[06/18/2004|11:01] C:\Program Files\ VideoMach-2.7.2
[09/13/2008|08:24] C:\Program Files\ Windows Media Player
[09/13/2008|08:24] C:\Program Files\ Windows NT
[08/13/2004|09:13] C:\Program Files\ WindowsUpdate
[11/23/2005|06:04] C:\Program Files\ WinRAR
[05/21/2006|06:34] C:\Program Files\ xerox
[02/18/2006|03:12] C:\Program Files\ Xfire
[03/03/2009|05:41] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[02/24/2009|12:31] C:\Program Files\Common Files\ Adobe
[02/24/2009|12:32] C:\Program Files\Common Files\ Adobe AIR
[11/22/2004|09:32] C:\Program Files\Common Files\ ArcSoft
[08/25/2006|09:11] C:\Program Files\Common Files\ Designer
[12/16/2005|10:04] C:\Program Files\Common Files\ InstallShield
[03/31/2007|10:35] C:\Program Files\Common Files\ Intuit
[06/03/2004|12:25] C:\Program Files\Common Files\ Java
[03/12/2005|07:30] C:\Program Files\Common Files\ Logitech
[02/13/2009|06:08] C:\Program Files\Common Files\ McAfee
[08/25/2006|09:11] C:\Program Files\Common Files\ Microsoft Shared
[05/21/2006|06:32] C:\Program Files\Common Files\ MSSoap
[05/21/2006|11:21] C:\Program Files\Common Files\ ODBC
[06/16/2004|07:28] C:\Program Files\Common Files\ Real
[05/21/2006|06:32] C:\Program Files\Common Files\ Services
[01/19/2009|10:53] C:\Program Files\Common Files\ Skype
[05/25/2004|09:07] C:\Program Files\Common Files\ Sonic
[05/21/2006|11:21] C:\Program Files\Common Files\ SpeechEngines
[05/25/2004|09:07] C:\Program Files\Common Files\ SureThing Shared
[09/13/2008|08:24] C:\Program Files\Common Files\ System
[02/23/2009|08:50] C:\Program Files\Common Files\ Wise Installation Wizard
[06/16/2004|07:28] C:\Program Files\Common Files\ xing shared

——————–\\ Process

( 30 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\JASONT~1\Cookies\jason tanner@advertising[1].txt

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-06 22:54:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections


No other infections found !

[F:31][D:3]-> C:\DOCUME~1\JASONT~1\LOCALS~1\Temp
[F:144][D:0]-> C:\DOCUME~1\JASONT~1\Cookies
[F:7303][D:12]-> C:\DOCUME~1\JASONT~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Thu 03/05/2009| 9:56 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - Fri 03/06/2009|22:56 - Option : [3]

——————–\\ Scan completed at 22:56:20
Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-03-08 18:43:07
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 10 GB (11%) free of 88 GB
Total RAM: 1535 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:43:12 PM, on 3/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Downloads\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Jason Tanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.the-holocron.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1176313003984
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A876265-EA61-4452-9EFF-8E8E80FC6F69}: NameServer = 68.94.156.1,68.94.157.1
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 7645 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-01-29 145424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-02-24 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-02-24 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-01-29 145424]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"=Mixer.exe /startup []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-08-11 86016]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2006-09-07 15872]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2007-11-01 582992]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2007-11-30 1164576]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-02-13 509784]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-02-24 148888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe boot []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-11-07 21633320]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-02-25 1830128]
"Messenger (Yahoo!)"=C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe [2009-02-20 4363504]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"=C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [2007-09-01 79408]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Red Storm Entertainment\Ghost Recon\GhostRecon.exe"="C:\Program Files\Red Storm Entertainment\Ghost Recon\GhostRecon.exe:*:Enabled:GhostRecon"
"C:\Program Files\Java\j2re1.4.2_04\bin\javaw.exe"="C:\Program Files\Java\j2re1.4.2_04\bin\javaw.exe:*:Enabled:javaw"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\GlobalSCAPE\CuteFTP\cutftp32.exe"="C:\Program Files\GlobalSCAPE\CuteFTP\cutftp32.exe:*:Enabled:Winsock FTP Client"
"C:\Program Files\Java\jre1.6.0_03\bin\javaw.exe"="C:\Program Files\Java\jre1.6.0_03\bin\javaw.exe:*:Enabled:Java™ Platform SE binary"
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"xpsptdlg.exe"="xpsptdlg.exe:*:enabled:Agent Protocol"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-03-05 10:53:10 —-A—- C:\lopR.txt
2009-03-05 10:52:36 —-D—- C:\Lop SD
2009-03-03 18:41:46 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\Yahoo!
2009-03-03 18:41:45 —-D—- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2009-03-03 18:40:20 —-D—- C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-03-02 22:03:48 —-D—- C:\rsit
2009-02-25 02:45:47 —-HDC—- C:\WINDOWS\$NtUninstallKB967715$
2009-02-24 01:58:39 —-SHD—- C:\RECYCLER
2009-02-24 01:46:05 —-A—- C:\WINDOWS\system32\javaws.exe
2009-02-24 01:46:05 —-A—- C:\WINDOWS\system32\javaw.exe
2009-02-24 01:46:05 —-A—- C:\WINDOWS\system32\java.exe
2009-02-24 01:45:16 —-D—- C:\Program Files\Java
2009-02-24 01:44:54 —-A—- C:\WINDOWS\system32\RENBA.tmp
2009-02-24 01:44:54 —-A—- C:\WINDOWS\system32\RENB9.tmp
2009-02-24 01:44:54 —-A—- C:\WINDOWS\system32\RENB8.tmp
2009-02-24 01:32:11 —-D—- C:\Program Files\Common Files\Adobe AIR
2009-02-23 09:52:19 —-D—- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-02-23 09:52:08 —-D—- C:\Program Files\SUPERAntiSpyware
2009-02-23 09:52:08 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\SUPERAntiSpyware.com
2009-02-23 09:50:57 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2009-02-21 00:28:23 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\Malwarebytes
2009-02-21 00:28:16 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2009-02-21 00:28:16 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-02-20 10:11:46 —-A—- C:\ComboFix.txt
2009-02-20 09:56:42 —-A—- C:\WINDOWS\zip.exe
2009-02-20 09:56:42 —-A—- C:\WINDOWS\VFIND.exe
2009-02-20 09:56:42 —-A—- C:\WINDOWS\SWXCACLS.exe
2009-02-20 09:56:42 —-A—- C:\WINDOWS\SWSC.exe
2009-02-20 09:56:42 —-A—- C:\WINDOWS\SWREG.exe
2009-02-20 09:56:42 —-A—- C:\WINDOWS\sed.exe
2009-02-20 09:56:42 —-A—- C:\WINDOWS\NIRCMD.exe
2009-02-20 09:56:42 —-A—- C:\WINDOWS\grep.exe
2009-02-20 09:56:42 —-A—- C:\WINDOWS\fdsv.exe
2009-02-19 01:55:41 —-D—- C:\Program Files\Trend Micro
2009-02-19 01:30:48 —-A—- C:\Boot.bak
2009-02-19 01:30:43 —-RASHD—- C:\cmdcons
2009-02-19 01:28:28 —-D—- C:\WINDOWS\ERDNT
2009-02-19 01:28:28 —-D—- C:\Qoobox
2009-02-14 15:06:59 —-D—- C:\Program Files\MSXML 4.0
2009-02-14 01:30:22 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\Mozilla
2009-02-14 01:30:10 —-D—- C:\Program Files\Mozilla Firefox
2009-02-14 00:09:21 —-A—- C:\WINDOWS\system32\lsdelete.exe
2009-02-13 23:29:07 —-DC—- C:\WINDOWS\system32\DRVSTORE
2009-02-13 23:25:02 —-HDC—- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-13 23:24:53 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-02-13 21:32:07 —-A—- C:\WINDOWS\isRS-000.tmp
2009-02-13 21:31:36 —-D—- C:\Binaries
2009-02-13 19:13:01 —-D—- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2009-02-13 19:08:02 —-D—- C:\Program Files\McAfee.com
2009-02-13 19:07:55 —-D—- C:\Program Files\Common Files\McAfee
2009-02-13 19:07:41 —-D—- C:\Program Files\McAfee
2009-02-13 18:20:19 —-D—- C:\Documents and Settings\All Users\Application Data\McAfee
2009-02-11 11:40:13 —-HDC—- C:\WINDOWS\$NtUninstallKB960715$

======List of files/folders modified in the last 1 months======

2009-03-08 18:43:09 —-D—- C:\WINDOWS\Temp
2009-03-08 18:43:09 —-D—- C:\WINDOWS\Prefetch
2009-03-08 18:42:45 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\Skype
2009-03-08 12:19:59 —-D—- C:\WINDOWS\system32
2009-03-08 12:19:59 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2009-03-08 12:18:22 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\skypePM
2009-03-07 18:11:17 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-03-05 10:51:33 —-D—- C:\Downloads
2009-03-03 18:41:43 —-D—- C:\Program Files\Yahoo!
2009-03-03 18:40:15 —-SHD—- C:\WINDOWS\Installer
2009-03-03 18:40:14 —-D—- C:\WINDOWS\WinSxS
2009-02-25 09:48:17 —-D—- C:\WINDOWS
2009-02-25 02:45:56 —-HD—- C:\WINDOWS\inf
2009-02-25 02:45:51 —-RSHDC—- C:\WINDOWS\system32\dllcache
2009-02-25 01:25:18 —-HD—- C:\WINDOWS\$hf_mig$
2009-02-25 01:25:16 —-D—- C:\WINDOWS\system32\CatRoot2
2009-02-24 01:45:21 —-A—- C:\WINDOWS\system32\deploytk.dll
2009-02-24 01:45:16 —-RD—- C:\Program Files
2009-02-24 01:32:33 —-D—- C:\Program Files\Adobe
2009-02-24 01:32:11 —-D—- C:\Program Files\Common Files
2009-02-24 01:31:51 —-D—- C:\Documents and Settings\All Users\Application Data\Adobe
2009-02-24 01:31:11 —-D—- C:\Program Files\Common Files\Adobe
2009-02-24 01:13:19 —-D—- C:\Documents and Settings\Jason Tanner\Application Data\AdobeUM
2009-02-21 09:52:05 —-A—- C:\WINDOWS\ntbtlog.txt
2009-02-21 09:45:54 —-A—- C:\WINDOWS\system32\advert.dll
2009-02-21 00:52:57 —-D—- C:\WINDOWS\system32\drivers
2009-02-20 10:04:20 —-A—- C:\WINDOWS\system.ini
2009-02-20 10:01:00 —-D—- C:\WINDOWS\system32\config
2009-02-20 09:59:50 —-D—- C:\WINDOWS\AppPatch
2009-02-19 01:30:48 —-RASH—- C:\boot.ini
2009-02-18 10:53:45 —-D—- C:\My Shared Folder
2009-02-18 10:53:45 —-D—- C:\Incomplete
2009-02-15 20:40:54 —-SD—- C:\WINDOWS\Downloaded Program Files
2009-02-14 00:58:39 —-A—- C:\WINDOWS\wininit.ini
2009-02-14 00:13:52 —-D—- C:\WINDOWS\PrimoPDF
2009-02-13 23:29:04 —-SD—- C:\WINDOWS\Tasks
2009-02-13 23:24:53 —-D—- C:\Program Files\Lavasoft
2009-02-13 21:32:08 —-A—- C:\WINDOWS\win.ini
2009-02-13 02:52:52 —-D—- C:\WINDOWS\SoftwareDistribution
2009-02-11 21:56:18 —-A—- C:\WINDOWS\system32\MRT.exe
2009-02-11 11:40:18 —-A—- C:\WINDOWS\imsins.BAK

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver; \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys []
R1 AvgAsCln;AVG Anti-Spyware Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys [2006-09-05 3968]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2007-11-22 201320]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2007-07-13 113952]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [1999-09-13 72704]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2001-10-30 280782]
R3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2001-08-17 117760]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2004-05-27 19968]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2007-11-22 79304]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2007-11-22 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2007-12-02 40488]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2003-03-31 12160]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 catchme;catchme; \??\C:\Combo-Fix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2007-11-22 33832]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 P1120VID;Creative WebCam NX Ultra; C:\WINDOWS\System32\DRIVERS\P1120Vid.sys [2003-09-18 759050]
S3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1); C:\WINDOWS\system32\DRIVERS\CamDrL20.sys [2004-05-21 245760]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard; C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe [2007-09-01 312880]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-02-24 152984]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-02-13 950096]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2009-01-23 203280]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-01-09 767976]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-01-25 2458128]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2007-08-15 359248]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2007-07-24 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2007-07-18 856864]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2007-12-05 695624]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2007-11-07 378184]

—————–EOF—————–
Your logs look clean, Great Job :thumbup:

Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]


Now for some cleanup..
Please download OTCleanIt and save it to Desktop.
  • Please make sure you are connecting to the Internet
  • Double-click OTCleanIt.exe
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

  • Install SpywareGuard - SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

here are some additional utilities that will enhance your safety

  • McAfee Site Advisor <= McAfee Site Advisor protects your browser against malicious sites and warns you when you go to one.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI