This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help infected with one or more trojans

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

anti-virus keeps saying infected with trojan horse clicker.zow and when i run scan whole computer the scan never seems to want to finish also when ever i search something on google and click the site i want it always redirects me to some random site
Hi sky3535

Welcome to the What the tech Forums
My name is mschroe919 and I am going help you
I would like to help you So if you would….
Please be patient and I will be back as soon as possible.

FIRST:


Please while I am gone do these steps:

Show hidden files, Here is how:

Windows XP or vista

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

NEXT:

Please download ATF Cleaner by Atribune.

Download it

HERE:

This program is for XP and Windows 2000 and vista
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

NEXT:

Malwarebytes' Anti-Malware

HERE

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
save and post the malwarebytes log when you get to the bottom of this page.
NEXT:

We need to download HijackThis, download it here
http://www.rosoftdownload.com/admin/images…/HJTInstall.exe
once downloaded click on it to install
By default it will install in c:\program files.Don't change the location
Then navigate to that directory and double-click on the hijackthis.exe file. When the program is started click on the Scan button and then the Save Log button to create a log of your information.
Once the log is saved please post it here .along with the Malwarebytes' Anti-Malware log
good luck

Be sure not to delete anything intill said ok to. also don't run any other cleanup programs till we
get done it may goof ours up.
Also if you have any questions feel fre to ask first.

When you post another HJT log and the Malwarebytes' Anti-Malware log , let me know how your PC is behavuing

I will be waiting to see new logs

mschroe919
Hi sky3535, two things to try: 1 go to where you got malware stored, change the name from mbam.exe to mine.exe to change name right click on mbam.exe and left click on rename make sure when you rename it tou add the .exe once name has changed try running it. 2 you can also try going into safe mode and runing the malware bytes there. did you do all the other stuff? if so send me the hjt log Good luck mschroe919
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:27:43 PM, on 6/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wltray.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Dynex G Desktop Card Adapter\DynexWCUI.exe
C:\Program Files\Keyspan\USB Server\nhciTask.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Broadcom Wireless Manager] C:\WINDOWS\system32\wltray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - Global Startup: Dynex Wireless Networking Utility.lnk = ?
O4 - Global Startup: Keyspan USB Server Task.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (file missing)
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A76211B-A2ED-4A88-A547-0527440E7642} (Install119 Control) - http://samsungdp.com/Install119.CAB
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://support.rexplorer.net/iftw_install//iftwclix.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O24 - Desktop Component 0: (no name) - http://www.fmls.com//FMLS/FMLS_CONSUMER/im…/home_right.gif

–
End of file - 8810 bytes
none of those options u gave me for Malwarebytes' Anti-Malware work cant even uninstall it either
Hi sky hey that rymes?

Download this:
pocket killbox from:


HERE:

Save to your Desktop and double click it to open it up.

In the 'Enter Full Path and Filename to Delete' box, copy and paste info and kill the file.

The path and file where you have the malwre bytes in

such as :

"C:\Program files\Malwarebytes' Anti-Malware\mbam.exe"

When you get that done let me know what you got we will try something different.

mschroe919
Hi

Download ComboFix to your Desktop.
Get it

HERE OR

HERE:

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
Close any open browsers

WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
Please do not re-connect your machine back to the Internet until Combofix has completely finished.


**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures

[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the C:\ComboFix.txt along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish

Note this also may need to change name

good luck mschroe919
Hi sorry about that… Lets try this one on it Go to where you have it stored right click on the icon combofix.exe and change the name to skit.exe and when name changed click on it to start it, and follow the steps I gave you for combofix, Good luck mschroe919
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:43:16 PM, on 6/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Broadcom Wireless Manager] C:\WINDOWS\system32\wltray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - Global Startup: Dynex Wireless Networking Utility.lnk = ?
O4 - Global Startup: Keyspan USB Server Task.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (file missing)
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A76211B-A2ED-4A88-A547-0527440E7642} (Install119 Control) - http://samsungdp.com/Install119.CAB
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://support.rexplorer.net/iftw_install//iftwclix.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O24 - Desktop Component 0: (no name) - http://www.fmls.com//FMLS/FMLS_CONSUMER/im…/home_right.gif

–
End of file - 7695 bytes
ComboFix 09-06-16.05 - Admin 06/17/2009 15:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.673 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\skit.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\_id.dat
c:\windows\system32\drivers\UACddtpqmdvkaiddxc.sys
c:\windows\system32\UACawuxjwylyoawhpx.dll
c:\windows\system32\UACbjkluiyougcwwmx.dll
c:\windows\system32\UACdlwowjwobpnkhdh.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiocjrqljtmoyvpa.dll
c:\windows\system32\UACmiubdooysveoxnd.dat
c:\windows\system32\UACnlguhylabefnmtp.dll
c:\windows\system32\UACnuodlytrmqydqvk.dll
c:\windows\system32\UACqppvrbkaksdfgjc.log
c:\windows\system32\UACsrpxtetdrxhlxud.dll
c:\windows\system32\uactmp.db
c:\windows\system32\UACxahrnqjumcvbphq.log
c:\windows\system32\UACyxebfdwvjlekvjn.db

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-05-17 to 2009-06-17 )))))))))))))))))))))))))))))))
.

2009-06-17 03:27 . 2009-06-17 03:29 ——– d—–w- C:\!KillBox
2009-06-16 12:07 . 2009-05-18 21:07 2052376 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-16 12:07 . 2009-06-11 12:32 3298072 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-16 12:07 . 2009-06-11 12:32 1261344 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-16 12:07 . 2009-06-11 12:32 829208 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-06-15 20:39 . 2009-06-15 20:42 ——– d—–w- c:\program files\Windows Live Safety Center
2009-06-15 20:20 . 2009-05-19 05:36 2884832 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\vwpt.exe
2009-06-15 20:20 . 2009-05-19 05:36 28 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\unregister.bat
2009-06-15 20:20 . 2009-05-19 05:36 30512 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\Uninstaller.exe
2009-06-15 20:20 . 2009-05-19 05:35 376568 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\unagi3.exe
2009-06-15 20:20 . 2009-05-19 05:36 1484856 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\toolbar.exe
2009-06-15 20:20 . 2009-05-19 05:35 11568 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\tbinst.dll
2009-06-15 20:20 . 2009-05-19 05:35 383128 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\tbsetup.exe
2009-06-15 20:20 . 2009-05-19 05:35 172840 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\setup.exe
2009-06-11 12:32 . 2009-06-11 12:32 1452312 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-05-21 00:53 . 2009-05-21 00:53 ——– d—–w- c:\program files\ESET
2009-05-19 18:17 . 2009-05-19 18:17 ——– d—–w- C:\rsit

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-17 03:29 . 2009-05-11 22:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-17 03:27 . 2009-02-23 02:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-16 12:06 . 2009-02-08 22:17 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-15 18:19 . 2009-02-08 22:17 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-06-15 17:19 . 2009-02-09 21:30 ——– d—–w- c:\documents and settings\Admin\Application Data\Azureus
2009-06-11 12:32 . 2009-02-08 22:17 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-26 17:20 . 2009-05-11 22:15 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 17:19 . 2009-05-11 22:15 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-23 14:34 . 2009-02-16 20:54 ——– d—–w- c:\documents and settings\Admin\Application Data\LimeWire
2009-05-22 20:40 . 2007-05-01 19:59 56 –sh–r- c:\windows\system32\C34AC63E24.sys
2009-05-22 20:40 . 2007-05-01 19:59 4288 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-19 05:36 . 2009-06-15 20:19 25 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\register.bat
2009-05-19 05:36 . 2009-06-15 20:19 97072 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\bsetutil.exe
2009-05-19 05:36 . 2009-06-15 20:19 142040 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\alsetup.exe
2009-05-19 05:36 . 2009-06-15 20:19 111920 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\AOLSearch.dll
2009-05-11 22:15 . 2009-05-11 22:15 ——– d—–w- c:\documents and settings\Admin\Application Data\Malwarebytes
2009-05-11 22:15 . 2009-05-11 22:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-09 16:27 . 2009-05-09 16:27 ——– d—–w- c:\program files\Trend Micro
2009-05-07 15:32 . 2004-08-10 18:51 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 23:47 . 2009-04-29 23:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-04-29 22:23 . 2009-02-08 22:17 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-04-29 22:22 . 2009-02-08 22:17 12552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-04-29 22:22 . 2009-02-08 22:17 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-29 04:56 . 2004-08-10 18:51 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-10 18:51 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-25 18:37 . 2009-02-23 00:55 ——– d—–w- c:\documents and settings\Admin\Application Data\GetRightToGo
2009-04-25 17:59 . 2009-02-09 21:35 7114736 —-a-w- c:\documents and settings\Admin\Application Data\Azureus\plugins\azemp\azmplay.exe
2009-04-19 10:49 . 2009-04-19 10:49 64512 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\HTML\item_templ\coach\RunGdp.exe
2009-04-19 10:47 . 2009-04-19 10:47 698511 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\HTML\AutoMaintenance\AutoMaintenance.dll
2009-04-19 10:47 . 2009-04-19 10:47 225280 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\HTML\AutoMaintenance\Images.dll
2009-04-19 10:46 . 2009-04-13 01:30 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-04-19 10:46 . 2009-03-16 16:56 ——– d—–w- c:\documents and settings\iris\Application Data\GTek
2009-04-19 10:46 . 2009-04-19 10:46 1896448 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\dplugins\2.0.1.571\DiagPlugin.dll
2009-04-19 10:46 . 2009-04-19 10:46 123138 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\MakeDesktopShortcut.EXE
2009-04-17 12:26 . 2004-08-10 18:51 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-16 01:37 . 2009-04-16 01:37 81920 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2009-04-16 01:37 . 2009-04-16 01:37 98304 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2009-04-16 01:37 . 2009-04-16 01:37 258352 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2009-04-16 01:37 . 2009-04-16 01:37 520192 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2009-04-16 01:37 . 2009-04-16 01:37 335872 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2009-04-16 01:37 . 2009-04-16 01:37 167936 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2009-04-15 14:51 . 2004-08-10 18:51 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-03-27 18:41 . 2009-03-27 18:41 152576 —-a-w- c:\documents and settings\Admin\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2007-08-04 00:31 . 2007-05-03 19:50 88 –sh–r- c:\windows\system32\243EC64AC3.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-05-10_15.26.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-19 21:59 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2009-02-19 21:59 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 44544 c:\windows\system32\pngfilt.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
- 2004-08-10 18:51 . 2009-05-10 15:01 63016 c:\windows\system32\perfc009.dat
+ 2004-08-10 18:51 . 2009-06-17 19:38 63016 c:\windows\system32\perfc009.dat
- 2007-08-13 22:54 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 22:54 . 2009-04-29 04:55 52224 c:\windows\system32\msfeedsbs.dll
- 2009-02-06 22:48 . 2009-03-09 19:58 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-02-06 22:48 . 2009-06-10 22:08 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2004-08-10 18:51 . 2009-04-29 04:55 27648 c:\windows\system32\jsproxy.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2007-08-13 22:39 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
+ 2007-08-13 22:39 . 2009-04-28 09:05 13824 c:\windows\system32\ieudinit.exe
- 2004-08-10 18:51 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 44544 c:\windows\system32\iernonce.dll
- 2004-08-10 18:51 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
+ 2004-08-10 18:51 . 2009-04-28 09:05 70656 c:\windows\system32\ie4uinit.exe
+ 2007-08-13 22:36 . 2009-04-29 04:55 63488 c:\windows\system32\icardie.dll
- 2007-08-13 22:36 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-10-18 22:44 . 2009-04-29 04:55 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2006-06-23 11:25 . 2009-04-29 04:55 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-18 22:44 . 2009-04-28 09:05 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2008-10-18 22:44 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-08-13 22:39 . 2009-04-29 04:55 44544 c:\windows\system32\dllcache\iernonce.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2009-04-29 04:55 78336 c:\windows\system32\dllcache\ieencode.dll
- 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
- 2007-08-13 22:39 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-13 22:39 . 2009-04-28 09:05 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-18 22:44 . 2009-04-29 04:55 63488 c:\windows\system32\dllcache\icardie.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
- 2006-03-13 22:43 . 2009-05-06 23:52 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-03-13 22:43 . 2009-06-16 19:31 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-03-13 22:43 . 2009-06-16 19:31 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-03-13 22:43 . 2009-05-06 23:52 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-03-13 22:43 . 2009-06-16 19:31 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2006-03-13 22:43 . 2009-05-06 23:52 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-23 02:09 . 2009-04-25 18:42 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 44544 c:\windows\ie7updates\KB969897-IE7\pngfilt.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 52224 c:\windows\ie7updates\KB969897-IE7\msfeedsbs.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 27648 c:\windows\ie7updates\KB969897-IE7\jsproxy.dll
+ 2009-06-12 07:01 . 2009-02-20 10:20 13824 c:\windows\ie7updates\KB969897-IE7\ieudinit.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 44544 c:\windows\ie7updates\KB969897-IE7\iernonce.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 78336 c:\windows\ie7updates\KB969897-IE7\ieencode.dll
+ 2009-06-12 07:01 . 2009-02-20 10:20 70656 c:\windows\ie7updates\KB969897-IE7\ie4uinit.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 63488 c:\windows\ie7updates\KB969897-IE7\icardie.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 233472 c:\windows\system32\webcheck.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 105984 c:\windows\system32\url.dll
- 2004-08-10 18:51 . 2009-05-10 15:01 402406 c:\windows\system32\perfh009.dat
+ 2004-08-10 18:51 . 2009-06-17 19:38 402406 c:\windows\system32\perfh009.dat
- 2004-08-10 18:51 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 102912 c:\windows\system32\occache.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 671232 c:\windows\system32\mstime.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 193024 c:\windows\system32\msrating.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 477696 c:\windows\system32\mshtmled.dll
- 2007-08-13 22:54 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
+ 2007-08-13 22:54 . 2009-04-29 04:55 459264 c:\windows\system32\msfeeds.dll
+ 2007-08-13 22:34 . 2009-04-29 04:55 268288 c:\windows\system32\iertutil.dll
- 2007-08-13 22:34 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 385024 c:\windows\system32\iedkcs32.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
- 2007-07-11 16:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
+ 2007-07-11 16:27 . 2009-04-29 04:55 383488 c:\windows\system32\ieapfltr.dll
+ 2004-08-10 18:51 . 2009-04-25 05:26 161792 c:\windows\system32\ieakui.dll
- 2004-08-10 18:51 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 230400 c:\windows\system32\ieaksie.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 153088 c:\windows\system32\ieakeng.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-10 18:57 . 2009-06-12 07:12 233576 c:\windows\system32\FNTCACHE.DAT
- 2004-08-10 18:57 . 2009-03-11 07:07 233576 c:\windows\system32\FNTCACHE.DAT
- 2004-08-10 18:51 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 133120 c:\windows\system32\extmgr.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 214528 c:\windows\system32\dxtrans.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 347136 c:\windows\system32\dxtmsft.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 827392 c:\windows\system32\dllcache\wininet.dll
+ 2007-08-13 22:54 . 2009-04-29 04:56 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-13 22:54 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2007-08-13 22:44 . 2009-04-29 04:56 105984 c:\windows\system32\dllcache\url.dll
- 2007-08-13 22:44 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
+ 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll
+ 2007-08-13 22:44 . 2009-04-29 04:56 102912 c:\windows\system32\dllcache\occache.dll
- 2007-08-13 22:44 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-18 22:44 . 2009-04-29 04:55 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
+ 2007-08-13 22:43 . 2009-04-25 05:27 636088 c:\windows\system32\dllcache\iexplore.exe
+ 2008-10-18 22:44 . 2009-04-29 04:55 268288 c:\windows\system32\dllcache\iertutil.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-08-13 22:39 . 2009-04-29 04:55 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-18 22:44 . 2009-04-29 04:55 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2007-08-13 21:56 . 2009-04-25 05:26 161792 c:\windows\system32\dllcache\ieakui.dll
- 2007-08-13 21:56 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2007-08-13 22:39 . 2009-04-29 04:55 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2007-08-13 22:39 . 2009-04-29 04:55 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2006-06-23 11:25 . 2009-04-29 04:55 133120 c:\windows\system32\dllcache\extmgr.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-06-23 11:25 . 2009-04-29 04:55 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-06-23 11:25 . 2009-04-29 04:55 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2007-08-13 22:39 . 2009-04-29 04:55 124928 c:\windows\system32\dllcache\advpack.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-10 18:50 . 2009-04-29 04:55 124928 c:\windows\system32\advpack.dll
- 2004-08-10 18:50 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2009-02-23 02:09 . 2009-04-25 18:42 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-06-12 07:01 . 2009-03-03 00:18 826368 c:\windows\ie7updates\KB969897-IE7\wininet.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 233472 c:\windows\ie7updates\KB969897-IE7\webcheck.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 105984 c:\windows\ie7updates\KB969897-IE7\url.dll
+ 2009-06-12 07:01 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB969897-IE7\spuninst\updspapi.dll
+ 2009-06-12 07:01 . 2008-07-09 07:38 231288 c:\windows\ie7updates\KB969897-IE7\spuninst\spuninst.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 102912 c:\windows\ie7updates\KB969897-IE7\occache.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 671232 c:\windows\ie7updates\KB969897-IE7\mstime.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 193024 c:\windows\ie7updates\KB969897-IE7\msrating.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 477696 c:\windows\ie7updates\KB969897-IE7\mshtmled.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 459264 c:\windows\ie7updates\KB969897-IE7\msfeeds.dll
+ 2009-06-12 07:01 . 2009-02-28 04:54 636072 c:\windows\ie7updates\KB969897-IE7\iexplore.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 268288 c:\windows\ie7updates\KB969897-IE7\iertutil.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 385024 c:\windows\ie7updates\KB969897-IE7\iedkcs32.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 383488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dll
+ 2009-06-12 07:01 . 2009-02-20 05:14 161792 c:\windows\ie7updates\KB969897-IE7\ieakui.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 230400 c:\windows\ie7updates\KB969897-IE7\ieaksie.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 153088 c:\windows\ie7updates\KB969897-IE7\ieakeng.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 133120 c:\windows\ie7updates\KB969897-IE7\extmgr.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 214528 c:\windows\ie7updates\KB969897-IE7\dxtrans.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 347136 c:\windows\ie7updates\KB969897-IE7\dxtmsft.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 124928 c:\windows\ie7updates\KB969897-IE7\advpack.dll
+ 2009-06-11 20:02 . 2009-06-11 20:02 452496 c:\windows\Downloaded Program Files\wlscBase.dll
+ 2009-05-16 16:10 . 2009-05-16 16:10 350064 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 1159680 c:\windows\system32\urlmon.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 3596288 c:\windows\system32\mshtml.dll
+ 2007-08-13 22:54 . 2009-04-29 04:55 6066176 c:\windows\system32\ieframe.dll
- 2007-08-13 22:54 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
+ 2008-10-18 19:12 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys
+ 2006-07-25 20:42 . 2009-04-29 04:56 1159680 c:\windows\system32\dllcache\urlmon.dll
+ 2006-07-28 11:30 . 2009-04-29 04:56 3596288 c:\windows\system32\dllcache\mshtml.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-18 22:44 . 2009-04-29 04:55 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2009-02-23 02:09 . 2009-06-12 07:06 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-02-23 02:09 . 2009-04-25 18:41 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 1160192 c:\windows\ie7updates\KB969897-IE7\urlmon.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 3595264 c:\windows\ie7updates\KB969897-IE7\mshtml.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 6066176 c:\windows\ie7updates\KB969897-IE7\ieframe.dll
+ 2009-06-12 07:01 . 2008-07-09 14:25 2455488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dat
+ 2009-05-16 16:06 . 2009-06-01 16:51 23635392 c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-02-22 26112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MMTray"="c:\progra~1\MUSICM~1\MUSICM~3\mm_tray.exe" [2005-09-09 110592]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\ssmmgr.exe" [2006-02-14 507904]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-03-02 1282048]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-11 1948440]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dynex Wireless Networking Utility.lnk - c:\program files\Dynex G Desktop Card Adapter\DynexWCUI.exe [2009-2-6 1462272]
Keyspan USB Server Task.lnk - c:\program files\Keyspan\USB Server\nhciTask.exe [2008-3-18 102400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-29 22:23 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UPS"=3 (0x3)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SCardSvr"=3 (0x3)
"RDSessMgr"=3 (0x3)
"Netlogon"=3 (0x3)
"CiSvc"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Documents and Settings\\Admin\\My Documents\\Azureus downloads\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Documents and Settings\\Admin\\My Documents\\wow\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Documents and Settings\\Admin\\My Documents\\wow\\World of Warcraft\\Launcher.exe"=
"c:\\Documents and Settings\\Admin\\My Documents\\wow\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\Documents and Settings\\Admin\\My Documents\\wow\\World of Warcraft\\WoW-3.0.1-to-3.0.2-enUS-Win-Update-downloader.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"57387:TCP"= 57387:TCP:Pando Media Booster
"57387:UDP"= 57387:UDP:Pando Media Booster

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2/8/2009 6:17 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/8/2009 6:17 PM 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/8/2009 6:17 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2/8/2009 6:17 PM 906520]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/8/2009 6:17 PM 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/19/2009 5:23 PM 24652]
R3 NHCIENUM;NHCIENUM;c:\windows\system32\drivers\nhcienum.sys [3/18/2008 2:33 PM 32000]
S3 NHCI;NHCI;c:\windows\system32\drivers\nhci.sys [3/18/2008 2:34 PM 30080]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.att.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: rexplorer.net
Trusted Zone: musicmatch.com\online
DPF: {0A76211B-A2ED-4A88-A547-0527440E7642} - hxxp://samsungdp.com/Install119.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-17 15:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-06-17 15:41
ComboFix-quarantined-files.txt 2009-06-17 19:41
ComboFix2.txt 2009-05-10 15:28

Pre-Run: 24,454,275,072 bytes free
Post-Run: 24,551,051,264 bytes free

387 — E O F — 2009-06-12 07:06
Hi Well that did it the name change. I have to take some time to analyze your logs, while I do that please let me know how your pc is doing now. mschroe919

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI