This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] TrojanDownloader/Win32/I.O

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:30:39 PM, on 7/17/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\sttray.exe
C:\Program Files\AudioBox USB\InstPresonusUSBDrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Advanced Woman Calendar\WomanCalendar.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [PreSonusUSBInstallApp] C:\Program Files\AudioBox USB\InstPresonusUSBDrv.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Advanced Woman Calendar] "C:\Program Files\Advanced Woman Calendar\WomanCalendar.exe" -m
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BsHelpCS - Brother Industries Ltd. - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9eba4d5aabe4e) (gupdate1c9eba4d5aabe4e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - C:\Windows\system32\libusbd-nt.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 11034 bytes
Nevermind i found it: Malwarebytes' Anti-Malware 1.39 Database version: 2421 Windows 6.0.6001 Service Pack 1 7/17/2009 2:58:44 PM mbam-log-2009-07-17 (14-58-44).txt Scan type: Full Scan (C:\|D:\|E:\|F:\|) Objects scanned: 431775 Time elapsed: 2 hour(s), 47 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Qoobox\quarantine\C\Windows\System32\drivers\MSIVXccwovvpmhwivumyloxvkhuptardqedmw.sys.vir (Rootkit.Agent) -> Quarantined and deleted successfully. c:\Windows\System32\MSINET.oca (Rogue.Trace) -> Quarantined and deleted successfully.
Hi there, almost done. :)

Run ComboFix

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

File::
F:\Program\FL Studio XXL Producer Edition v8.0.0 [TSRh Crack][h33t][matt14]\flstudio_8.0_install.exe
F:\Program\My Plugins\AudioRealism BassLine VSTi v2.1.0 Incl.Keygen - AiR\Setup.exe
F:\Program\My Plugins\Sonalksis.All.Plugins.Bundle.VST.DX.RTAS.v2.04.Incl.Keygen-AiR\Keygen.exe
F:\Program\Nero 7\Nero-7.8.5.0_eng_trial.exe

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

In your next reply, please include:
  • ComboFix log
  • A new HijackThis log

Regards,
Adam
Im not exactly sure if it finished because it said something about uploading to the server for further anylisis but like the connection timed out and the upload did not finish. Here is the log: ComboFix 09-07-12.03 - Robert 07/17/2009 18:41.4.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1022.295 [GMT -4:00] Running from: c:\users\[removed]\Desktop\Combo-Fix.exe Command switches used :: c:\users\Robert\Desktop\CFScript.txt SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} FILE :: "f:\program\FL Studio XXL Producer Edition v8.0.0 [TSRh Crack][h33t][matt14]\flstudio_8.0_install.exe" "f:\program\My Plugins\AudioRealism BassLine VSTi v2.1.0 Incl.Keygen - AiR\Setup.exe" "f:\program\My Plugins\Sonalksis.All.Plugins.Bundle.VST.DX.RTAS.v2.04.Incl.Keygen-AiR\Keygen.exe" "f:\program\Nero 7\Nero-7.8.5.0_eng_trial.exe" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . f:\program\FL Studio XXL Producer Edition v8.0.0 [TSRh Crack][h33t][matt14]\flstudio_8.0_install.exe f:\program\My Plugins\AudioRealism BassLine VSTi v2.1.0 Incl.Keygen - AiR\Setup.exe f:\program\My Plugins\Sonalksis.All.Plugins.Bundle.VST.DX.RTAS.v2.04.Incl.Keygen-AiR\Keygen.exe f:\program\Nero 7\Nero-7.8.5.0_eng_trial.exe . ((((((((((((((((((((((((( Files Created from 2009-06-17 to 2009-07-17 ))))))))))))))))))))))))))))))) . 2009-07-17 22:52 . 2009-07-17 22:52 ——– d—–w- c:\users\Robert\AppData\Local\temp 2009-07-17 19:22 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090715.003\Scxpx86.dll 2009-07-17 19:22 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090715.003\IDSvix86.sys 2009-07-17 19:22 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090715.003\SymIDSco.sys 2009-07-17 19:22 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090715.003\IDSxpx86.dll 2009-07-17 19:22 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090715.003\SymIDSI.dll 2009-07-17 19:22 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090715.003\IDSviA64.sys 2009-07-17 19:22 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090715.003\IDS9xx86.dll 2009-07-17 16:49 . 2009-07-13 08:00 87888 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090717.006\NAVENG.SYS 2009-07-17 16:49 . 2009-07-13 08:00 875728 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090717.006\NAVEX15.SYS 2009-07-17 16:49 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090717.006\EECTRL.SYS 2009-07-17 16:49 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090717.006\ECMSVR32.DLL 2009-07-17 16:49 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090717.006\CCERASER.DLL 2009-07-17 16:49 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090717.006\NAVENG32.DLL 2009-07-17 16:49 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090717.006\NAVEX32A.DLL 2009-07-17 16:49 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090717.006\ERASER.SYS 2009-07-17 16:03 . 2009-07-17 16:03 3775176 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-07-17 13:20 . 2009-07-17 13:20 ——– d—–w- c:\program files\ESET 2009-07-17 08:11 . 2009-07-13 08:00 87888 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090716.055\NAVENG.SYS 2009-07-17 08:11 . 2009-07-13 08:00 875728 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090716.055\NAVEX15.SYS 2009-07-17 08:11 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090716.055\EECTRL.SYS 2009-07-17 08:11 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090716.055\ECMSVR32.DLL 2009-07-17 08:11 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090716.055\CCERASER.DLL 2009-07-17 08:11 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090716.055\NAVENG32.DLL 2009-07-17 08:11 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090716.055\NAVEX32A.DLL 2009-07-17 08:11 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090716.055\ERASER.SYS 2009-07-15 03:49 . 2009-06-15 15:24 156672 —-a-w- c:\windows\system32\t2embed.dll 2009-07-15 03:49 . 2009-06-15 15:20 72704 —-a-w- c:\windows\system32\fontsub.dll 2009-07-15 03:49 . 2009-06-15 12:52 289792 —-a-w- c:\windows\system32\atmfd.dll 2009-07-15 03:49 . 2009-06-15 15:20 10240 —-a-w- c:\windows\system32\dciman32.dll 2009-07-13 09:29 . 2009-07-13 09:29 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe 2009-07-13 07:59 . 2009-07-13 08:03 ——– d-s—w- C:\ComboFix 2009-07-13 02:46 . 2009-07-17 22:22 ——– d—–w- c:\users\Robert\AppData\Roaming\uTorrent 2009-07-12 08:26 . 2009-07-12 08:26 ——– d—–w- C:\_OTM 2009-07-12 07:25 . 2009-07-12 07:26 ——– d—–w- C:\rsit 2009-07-12 06:26 . 2009-07-12 06:26 ——– d—–w- c:\users\Robert\AppData\Roaming\Malwarebytes 2009-07-12 06:23 . 2009-07-13 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-12 06:23 . 2009-07-13 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-07-12 06:23 . 2009-07-12 06:23 ——– d—–w- c:\programdata\Malwarebytes 2009-07-12 06:23 . 2009-07-17 16:03 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-07-12 01:16 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX32A.DLL 2009-07-12 01:16 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG.SYS 2009-07-12 01:16 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX15.SYS 2009-07-12 01:16 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\EECTRL.SYS 2009-07-12 01:16 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ECMSVR32.DLL 2009-07-12 01:16 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\CCERASER.DLL 2009-07-12 01:16 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG32.DLL 2009-07-12 01:16 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ERASER.SYS 2009-07-11 07:09 . 2009-07-13 23:30 ——– d—–w- c:\program files\Trend Micro 2009-07-10 22:43 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\Scxpx86.dll 2009-07-10 22:43 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSvix86.sys 2009-07-10 22:43 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSco.sys 2009-07-10 22:43 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSxpx86.dll 2009-07-10 22:43 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSI.dll 2009-07-10 22:43 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSviA64.sys 2009-07-10 22:43 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDS9xx86.dll 2009-07-10 15:27 . 2009-07-13 00:59 ——– d—–w- c:\windows\.jagex_cache_32 2009-07-09 05:17 . 2009-07-09 05:31 ——– d—–w- c:\program files\MasterWriter 2.0 2009-07-07 00:25 . 2009-07-07 00:25 ——– d—–w- c:\users\Robert\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150040} 2009-07-02 12:25 . 2009-07-11 06:20 ——– d—–w- c:\users\Robert\Tracing 2009-07-02 07:30 . 2009-07-02 07:30 ——– d—–w- c:\program files\Microsoft Office Outlook Connector 2009-07-02 07:25 . 2009-07-02 07:25 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition 2009-07-02 07:21 . 2009-07-02 07:21 ——– d—–w- c:\program files\Windows Live SkyDrive 2009-07-02 07:21 . 2009-07-11 06:39 ——– d—–w- c:\program files\Windows Live 2009-07-02 06:33 . 2009-05-09 05:34 71680 —-a-w- c:\windows\system32\iesetup.dll 2009-07-02 06:33 . 2009-05-09 05:50 915456 —-a-w- c:\windows\system32\wininet.dll 2009-06-28 04:05 . 2009-06-28 04:05 ——– d—–w- c:\users\Robert\AppData\Roaming\QQ Games Plugin 2009-06-28 04:03 . 2009-06-28 04:08 ——– d—–w- c:\programdata\Tencent 2009-06-28 04:03 . 2009-06-28 04:03 ——– d—–w- c:\program files\Tencent 2009-06-28 04:00 . 2009-06-28 04:00 5946704 —-a-w- c:\programdata\AOL Downloads\aimqqgames\QQSetup65.exe 2009-06-28 03:59 . 2009-06-28 03:59 1144808 —-a-w- c:\programdata\AOL Downloads\aimtunes\AIMTunes.exe 2009-06-28 03:58 . 2009-06-28 03:58 ——– d—–w- c:\programdata\acccore 2009-06-28 03:56 . 2009-06-28 04:04 ——– d—–w- c:\program files\AIM6 2009-06-27 05:42 . 2009-06-27 05:42 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2009-06-26 19:22 . 2009-06-26 19:22 ——– d—–w- c:\users\Robert\New Folder 2009-06-26 10:22 . 2009-06-26 10:29 ——– d—–w- c:\program files\4WomenOnly 2009-06-26 10:17 . 2009-06-26 10:17 ——– d—–w- c:\program files\Advanced Woman Calendar 2009-06-26 01:40 . 2009-06-26 01:40 ——– d—–w- c:\users\Robert\AppData\Roaming\SoftOrbits 2009-06-23 15:20 . 2009-06-23 15:20 ——– d—–w- c:\users\Robert\AppData\Local\SourceTec 2009-06-20 01:10 . 2009-06-20 01:11 ——– d—–w- c:\users\Robert\AppData\Local\Deployment . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-17 19:02 . 2007-11-14 23:57 12 —-a-w- c:\windows\bthservsdp.dat 2009-07-15 07:07 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2009-07-14 22:37 . 2009-02-27 04:27 ——– d—–w- c:\programdata\NOS 2009-07-14 22:36 . 2009-02-27 04:27 ——– d—–w- c:\program files\NOS 2009-07-13 09:34 . 2007-07-13 02:56 ——– d—–w- c:\program files\Common Files\Adobe 2009-07-13 09:31 . 2008-11-20 15:36 ——– d—–w- c:\program files\Common Files\Adobe AIR 2009-07-13 09:28 . 2007-04-18 02:01 7592 —-a-w- c:\users\Robert\AppData\Local\d3d9caps.dat 2009-07-13 09:19 . 2007-02-08 08:09 ——– d—–w- c:\program files\Java 2009-07-11 06:24 . 2007-08-11 03:20 ——– d—–w- c:\program files\The Rosetta Stone 2009-07-11 06:23 . 2007-02-08 08:26 ——– d—–w- c:\program files\Google 2009-07-10 02:19 . 2007-03-13 01:49 115728 —-a-w- c:\users\Robert\AppData\Local\GDIPFONTCACHEV1.DAT 2009-07-02 07:22 . 2009-01-23 16:32 ——– d—–w- c:\program files\Microsoft 2009-06-28 04:00 . 2007-03-13 23:38 ——– d—–w- c:\programdata\AOL Downloads 2009-06-28 03:58 . 2007-06-08 13:46 ——– d—–w- c:\programdata\Viewpoint 2009-06-28 03:57 . 2007-03-13 23:40 ——– d—–w- c:\program files\Common Files\AOL 2009-06-28 03:52 . 2007-03-13 23:40 ——– d—–w- c:\programdata\AOL 2009-06-13 17:11 . 2007-10-29 23:11 ——– d—–w- c:\users\Robert\AppData\Roaming\Apple Computer 2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iTunes 2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iPod 2009-06-13 16:44 . 2009-06-13 16:28 ——– d—–w- c:\program files\Common Files\Apple 2009-06-13 16:41 . 2008-02-21 01:51 ——– d—–w- c:\program files\Bonjour 2009-06-13 16:40 . 2009-06-13 16:39 ——– d—–w- c:\program files\QuickTime 2009-06-13 16:32 . 2009-06-13 16:31 ——– d—–w- c:\program files\Apple Software Update 2009-06-12 21:34 . 2009-06-12 21:34 ——– d—–w- c:\program files\Common Files\xing shared 2009-06-12 21:33 . 2009-03-29 23:13 ——– d—–w- c:\program files\Common Files\Real 2009-06-12 18:00 . 2009-06-12 18:00 ——– d—–w- c:\users\Robert\AppData\Roaming\TVU Networks 2009-06-12 17:58 . 2009-06-12 17:58 ——– d—–w- c:\program files\Satellite TV for PC 2009-06-10 00:25 . 2009-05-25 11:59 ——– d—–w- c:\program files\Pcsx2_0.9.4(2) 2009-06-10 00:24 . 2007-03-13 23:42 ——– d—–w- c:\program files\MySpace 2009-06-08 16:14 . 2009-06-08 16:14 ——– d—–w- c:\program files\LG Electronics 2009-06-08 16:14 . 2007-02-08 08:09 ——– d–h–w- c:\program files\InstallShield Installation Information 2009-06-05 17:57 . 2009-06-05 17:57 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe 2009-06-05 15:42 . 2009-06-05 15:42 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2009-06-05 15:42 . 2009-06-05 15:42 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll 2009-06-04 21:44 . 2009-06-04 21:44 ——– d—–w- c:\program files\BitPim 2009-05-24 14:34 . 2009-05-24 14:34 ——– d—–w- c:\program files\LibUSB-Win32-0.1.10.1 2009-05-21 15:33 . 2009-01-05 11:29 410984 —-a-w- c:\windows\system32\deploytk.dll 2009-05-16 12:37 . 2009-05-16 12:37 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll 2009-05-13 12:32 . 2009-05-13 08:00 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys 2009-05-13 12:32 . 2009-05-13 08:00 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys 2009-05-13 12:32 . 2009-05-13 08:00 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys 2009-05-13 12:32 . 2009-05-13 08:00 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll 2009-05-13 12:32 . 2009-05-13 08:00 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll 2009-05-13 12:32 . 2009-05-13 08:00 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll 2009-05-13 12:32 . 2009-05-13 08:00 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys 2009-05-13 12:32 . 2009-02-26 22:23 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll 2009-05-08 13:35 . 2008-08-14 11:57 73312 —-a-w- c:\windows\system32\drivers\adfs.sys 2009-04-30 12:37 . 2009-06-14 00:07 293376 —-a-w- c:\windows\system32\psisdecd.dll 2009-04-30 12:37 . 2009-06-14 00:07 428544 —-a-w- c:\windows\system32\EncDec.dll 2009-04-23 12:43 . 2009-06-10 05:45 784896 —-a-w- c:\windows\system32\rpcrt4.dll 2009-04-23 12:42 . 2009-06-10 05:45 636928 —-a-w- c:\windows\system32\localspl.dll 2009-04-21 11:55 . 2009-06-10 05:45 2033152 —-a-w- c:\windows\system32\win32k.sys 2009-04-01 02:47 . 2009-02-26 23:44 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll 2007-02-08 15:54 . 2007-02-08 15:54 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((( SnapShot@2009-07-12_22.54.55 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-15 03:49 . 2009-06-15 14:58 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\lpk.dll + 2009-07-15 03:49 . 2009-06-15 14:58 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\fontsub.dll + 2009-07-15 03:49 . 2009-06-15 14:58 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\dciman32.dll + 2009-07-15 03:49 . 2009-06-15 12:45 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\atmlib.dll + 2009-07-15 03:49 . 2009-06-15 14:52 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\lpk.dll + 2009-07-15 03:49 . 2009-06-15 14:52 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\fontsub.dll + 2009-07-15 03:49 . 2009-06-15 14:51 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\dciman32.dll + 2009-07-15 03:49 . 2009-04-11 06:28 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\atmlib.dll + 2009-07-15 03:49 . 2009-06-15 15:22 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\lpk.dll + 2009-07-15 03:49 . 2009-06-15 15:20 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\fontsub.dll + 2009-07-15 03:49 . 2009-06-15 15:19 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\dciman32.dll + 2009-07-15 03:49 . 2009-06-15 15:19 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\atmlib.dll + 2008-09-13 19:53 . 2008-01-19 07:34 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\lpk.dll + 2009-07-15 03:49 . 2009-06-15 15:20 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\fontsub.dll + 2009-07-15 03:49 . 2009-06-15 15:20 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\dciman32.dll + 2006-11-02 08:38 . 2006-11-02 09:46 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\atmlib.dll + 2009-07-15 03:49 . 2009-06-15 15:04 24064 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\lpk.dll + 2009-07-15 03:49 . 2009-06-15 15:03 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\fontsub.dll + 2009-07-15 03:49 . 2009-06-15 15:02 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\dciman32.dll + 2009-07-15 03:49 . 2009-06-15 15:02 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\atmlib.dll + 2009-07-15 03:49 . 2009-06-15 15:23 24064 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\lpk.dll + 2009-07-15 03:49 . 2009-06-15 15:22 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\fontsub.dll + 2009-07-15 03:49 . 2009-06-15 15:21 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\dciman32.dll + 2009-07-15 03:49 . 2009-06-15 15:20 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\atmlib.dll + 2007-02-08 08:40 . 2009-07-17 19:08 73040 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2007-03-13 01:49 . 2009-07-17 19:09 15780 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1592213791-1963367186-16139517-1001_UserData.bin + 2007-03-13 02:44 . 2009-07-17 22:16 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2007-03-13 02:44 . 2009-07-12 22:52 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2007-03-13 02:44 . 2009-07-12 22:52 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2007-03-13 02:44 . 2009-07-17 22:16 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2007-03-13 02:44 . 2009-07-12 22:52 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2007-03-13 02:44 . 2009-07-17 22:16 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-13 09:32 . 2009-07-13 09:32 26624 c:\windows\Installer\c8f4e.msi - 2007-02-08 08:26 . 2009-07-11 04:21 23040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe + 2007-02-08 08:26 . 2009-07-15 07:06 23040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe - 2007-02-08 08:26 . 2009-07-11 04:21 61440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe + 2007-02-08 08:26 . 2009-07-15 07:06 61440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe - 2007-02-08 08:26 . 2009-07-11 04:21 27136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe + 2007-02-08 08:26 . 2009-07-15 07:06 27136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe + 2007-02-08 08:26 . 2009-07-15 07:06 11264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe - 2007-02-08 08:26 . 2009-07-11 04:21 11264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe + 2007-02-08 08:26 . 2009-07-15 07:06 12288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe - 2007-02-08 08:26 . 2009-07-11 04:21 12288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2007-03-15 09:59 . 2009-07-17 19:03 7274 c:\windows\System32\WDI\ERCQueuedResolutions.dat - 2007-03-15 09:59 . 2009-07-11 19:06 7274 c:\windows\System32\WDI\ERCQueuedResolutions.dat - 2009-07-12 22:52 . 2009-07-12 22:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2009-07-17 19:06 . 2009-07-17 19:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2009-07-17 19:06 . 2009-07-17 19:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-07-12 22:52 . 2009-07-12 22:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2007-02-08 08:26 . 2009-07-15 07:06 4096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe - 2007-02-08 08:26 . 2009-07-11 04:21 4096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe + 2009-07-15 03:49 . 2009-06-15 12:45 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\atmfd.dll + 2009-07-15 03:49 . 2009-06-15 12:42 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\atmfd.dll + 2009-07-15 03:49 . 2009-06-15 12:56 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\atmfd.dll + 2009-07-15 03:49 . 2009-06-15 12:52 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\atmfd.dll + 2009-07-15 03:49 . 2009-06-15 12:53 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\atmfd.dll + 2009-07-15 03:49 . 2009-06-15 13:03 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\atmfd.dll + 2009-07-15 03:49 . 2009-06-15 15:00 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6002.22152_none_b7fc28a4355e72c9\t2embed.dll + 2009-07-15 03:49 . 2009-06-15 14:53 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6002.18051_none_b7718b8f1c41b9a8\t2embed.dll + 2009-07-15 03:49 . 2009-06-15 15:26 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6001.22450_none_b613b6283839eaf7\t2embed.dll + 2009-07-15 03:49 . 2009-06-15 15:24 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6001.18272_none_b57678331f2ab896\t2embed.dll + 2009-07-15 03:49 . 2009-06-15 15:09 156160 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6000.21067_none_b4297fd83b155d73\t2embed.dll + 2009-07-15 03:49 . 2009-06-15 15:29 156160 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6000.16870_none_b38e38f92205f4f7\t2embed.dll + 2006-11-02 13:05 . 2009-07-17 19:09 104472 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin + 2006-11-02 10:33 . 2009-07-15 05:07 611788 c:\windows\System32\perfh009.dat - 2006-11-02 10:33 . 2009-07-12 08:13 611788 c:\windows\System32\perfh009.dat - 2006-11-02 10:33 . 2009-07-12 08:13 106796 c:\windows\System32\perfc009.dat + 2006-11-02 10:33 . 2009-07-15 05:07 106796 c:\windows\System32\perfc009.dat - 2009-07-02 12:44 . 2009-07-12 10:31 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2009-07-02 12:44 . 2009-07-16 17:39 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2007-02-08 08:26 . 2009-07-15 07:06 409600 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe - 2007-02-08 08:26 . 2009-07-11 04:21 409600 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe - 2007-02-08 08:26 . 2009-07-11 04:21 286720 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe + 2007-02-08 08:26 . 2009-07-15 07:06 286720 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe - 2007-02-08 08:26 . 2009-07-11 04:21 249856 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe + 2007-02-08 08:26 . 2009-07-15 07:06 249856 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe - 2007-02-08 08:26 . 2009-07-11 04:21 794624 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe + 2007-02-08 08:26 . 2009-07-15 07:06 794624 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe + 2007-02-08 08:26 . 2009-07-15 07:06 135168 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe - 2007-02-08 08:26 . 2009-07-11 04:21 135168 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe + 2009-07-15 03:49 . 2009-06-17 08:02 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22160_none_f4b74f0181eee730\OESpamFilter.dat + 2009-07-15 03:49 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18056_none_f43e83de68c3c37f\OESpamFilter.dat + 2009-07-15 03:49 . 2009-06-17 07:30 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22459_none_f2e4af9f84b85a2a\OESpamFilter.dat + 2009-07-15 03:49 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18278_none_f24470cc6babdbc4\OESpamFilter.dat + 2009-07-15 03:49 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21074_none_f0e3a5eb87a6b883\OESpamFilter.dat + 2009-07-15 03:49 . 2009-06-17 07:36 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16876_none_f05c31926e871825\OESpamFilter.dat - 2006-11-02 10:22 . 2009-07-11 06:40 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat + 2006-11-02 10:22 . 2009-07-17 19:04 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat - 2006-11-02 12:47 . 2009-07-10 02:23 2524136 c:\windows\System32\FNTCACHE.DAT + 2006-11-02 12:47 . 2009-07-15 07:20 2524136 c:\windows\System32\FNTCACHE.DAT + 2009-07-17 19:03 . 2009-07-17 19:03 1500032 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat + 2009-06-30 15:30 . 2009-06-30 15:30 5520384 c:\windows\Installer\d1349e.msp + 2009-07-13 09:37 . 2009-07-13 09:37 3938816 c:\windows\Installer\c8f6b.msi + 2006-11-02 10:24 . 2009-07-07 15:10 24539592 c:\windows\System32\mrt.exe + 2009-06-13 07:02 . 2009-07-15 07:15 100604308 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136] "AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-02 4608] "SRS Audio Sandbox"="c:\program files\SRS Labs\Audio Sandbox\SRSSSC.exe" [2007-09-08 3153920] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544] "Advanced Woman Calendar"="c:\program files\Advanced Woman Calendar\WomanCalendar.exe" [2009-05-23 1503232] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-27 1540096] "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2006-11-17 17920] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-10-13 184320] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544] "PreSonusUSBInstallApp"="c:\program files\AudioBox USB\InstPresonusUSBDrv.exe" [2008-03-07 28672] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048] "osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-12 198160] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-01-12 303104] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-2-8 50688] QuickSet.lnk - c:\windows\Installer\{53A01CC6-14B0-4512-A2E7-10D39BF83DC4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-2-8 45056] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{DC710089-7342-417F-A0FA-EA1011418106}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent "{8405E45A-A992-480B-91C3-BDCC3100CC25}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{6F84580A-2584-434F-8547-37BE87270674}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{4B3691E0-8E97-479D-B685-16C91E95CBE8}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent "{6532F09B-8FC9-40BA-8690-D94EBB1ACBDD}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent "TCP Query User{176AF534-1FED-46AF-9AF6-1F2D17C4034B}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath "UDP Query User{D94FA29A-0081-455B-AAA5-77B189ACE72C}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath "{C6222461-1E4D-48BC-9426-06A3D575611A}"= UDP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project "{26E34F77-6589-480B-8314-2F0FF6F3B35C}"= TCP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project "{4F357201-4322-4748-A572-57E518BC2692}"= UDP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP) "{33C59A06-EAA6-4B06-A8A8-A02AFB6C0450}"= TCP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP) "TCP Query User{972126A1-FFB1-40AA-A487-EDB57C69F396}c:\\stubinstaller.exe"= UDP:C:\stubinstaller.exe:LimeWire swarmed installer "UDP Query User{08FE4F19-82BE-41A1-981B-A6E200035140}c:\\stubinstaller.exe"= TCP:C:\stubinstaller.exe:LimeWire swarmed installer "{39626CD8-ADEE-4ED5-A522-B8BE4367839E}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{36E3D7E5-3AC9-452B-995F-E431754D9694}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire "TCP Query User{50774B62-755F-426B-BA2A-02367C248FD8}c:\\program files\\america's army\\system\\armyops.exe"= UDP:c:\program files\america's army\system\armyops.exe:ArmyOps "UDP Query User{699E8109-8EC9-45D5-B124-78D4CECC6789}c:\\program files\\america's army\\system\\armyops.exe"= TCP:c:\program files\america's army\system\armyops.exe:ArmyOps "TCP Query User{7F12EB81-973C-42BE-B20C-8AD6CBEDE1CD}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent "UDP Query User{C99F839B-F361-48CE-8ED4-1B05B0427AB4}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent "TCP Query User{11CAFF35-683B-4264-A107-0CD434DBF06B}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= UDP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home "UDP Query User{9CD00152-8430-4809-9267-A35C2A4457BA}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= TCP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home "{0E737215-4FCF-4A34-B3F5-12AD135DD972}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB "{1B111988-17EE-43ED-B972-5517B49E42DB}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB "{41BE85E8-EA12-4202-8761-0D4796BB177B}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA "{F5CF6DEF-A246-43FF-8F3C-6BE0235F11B2}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA "TCP Query User{E2C7BFD9-15E5-4E1C-8224-D3584D59088C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{9C831B6D-4CB2-454F-9089-3AF58DBD4AC3}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer "TCP Query User{DBD29491-FF3D-43F9-90ED-44CC95386DCD}c:\\program files\\quicktime\\quicktimeplayer.exe"= UDP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application "UDP Query User{A380A176-6079-43CB-A92E-32FCEEA9BEC7}c:\\program files\\quicktime\\quicktimeplayer.exe"= TCP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application "TCP Query User{3AC313D9-B6B3-495C-8C13-500BB0EA49C7}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= UDP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe "UDP Query User{1982024B-D1E4-4F70-839F-6635AD27A497}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= TCP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe "TCP Query User{C05E66C8-281F-45E7-B14E-CF88DD3147B8}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:UDP:c:\program files\microsoft games\halo\halo.exe:Halo "UDP Query User{EB58509F-411D-4429-A0FD-2CD055BA3B95}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:TCP:c:\program files\microsoft games\halo\halo.exe:Halo "{2C13D723-369B-44D5-8C32-8135E6B16B71}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas "{B3796AEB-60D7-4DEF-BFE5-BB9171F4803A}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas "{DB5A49BC-BDCA-4BBB-8CF1-BEBFF13098E2}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater "{FCB7312A-3871-4FC9-821E-71988B8544AC}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater "{30BCEC95-2E5A-4C61-8D40-C3B9FFD3823B}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS "{037AC626-54D7-4530-B3D8-BB570E3D8C16}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS "TCP Query User{CD6EC63F-B479-473B-B94F-56C99452F37A}c:\\program files\\kuma games\\kumaclient.exe"= UDP:c:\program files\kuma games\kumaclient.exe:KumaClient "UDP Query User{BEB615F7-77C8-4EEF-805F-444D585E6EDA}c:\\program files\\kuma games\\kumaclient.exe"= TCP:c:\program files\kuma games\kumaclient.exe:KumaClient "{5D1DEC78-A955-4D8A-8296-811BDF1617A0}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil "{DF77B589-E554-4ADC-8108-874E486BA6C6}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil "TCP Query User{0C521428-3F98-4271-B54D-F6B44CF3EC49}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter "UDP Query User{6CCA7FD4-2B5B-49EB-9341-1CEACD116E8F}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter "TCP Query User{0DF51FA7-6AFB-4AB0-8E51-D9A5546224D3}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= UDP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe "UDP Query User{11D209CA-9190-4F46-8CFA-15933A36E47C}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= TCP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe "TCP Query User{0AB1783F-77DA-428F-A04E-8190DB0A0AF7}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:utorrent "UDP Query User{9D214FD0-B98C-47D1-8CA6-FD35255964A0}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:utorrent "TCP Query User{50942DBF-744F-4A91-8D9B-AAF9E80C6482}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM "UDP Query User{2D2ED0DB-41F5-4E5D-9F7E-A25BC637E633}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM "TCP Query User{BE578BD9-8465-4D6C-9104-D8731100F238}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:UDP:c:\program files\america's army\system\armyops.exe:ArmyOps "UDP Query User{DCE00D38-E3F7-4059-AA29-0CCB1171B992}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:TCP:c:\program files\america's army\system\armyops.exe:ArmyOps "{80CBB081-7B44-4297-BC34-684ECB632924}"= Disabled:UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11 "{D2F76F1D-9440-4DF7-AB3E-1631127E3FE9}"= Disabled:TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11 "{BA6434C4-DCAC-4FF5-82D9-D7445E776408}"= UDP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service "{CB372408-8C36-4775-B0F0-DF0AE2280357}"= TCP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service "{F7236639-1ECF-4334-8244-2138D2278732}"= UDP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service "{EFFBAA4E-D072-49BD-B58B-B586E631F96B}"= TCP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service "{34B5A9D7-4FFB-4581-AC04-B5508393A17B}"= UDP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service "{4F730A66-4CEC-44A0-9025-6E32E7CF3626}"= TCP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service "{6C52A495-FE39-42B0-8F73-8DEA79E5C6B4}"= UDP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface "{AEDB5741-E4CE-4DB3-8BE5-F9B07B64DB14}"= TCP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface "{A0A1FD56-A36B-443B-B6B4-45F537345010}"= UDP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service "{DBCD57CA-719A-45A7-9E5B-12CE6E6FA46D}"= TCP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service "{331A8417-C522-4DC1-A96D-99C6B0B2414F}"= Disabled:TCP:5353:LocalSubnet:LocalSubnet:mDNS-SD/Bonjour "{F94507A9-E86D-4B26-A05D-98640DE4B435}"= Disabled:UDP:7288:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7288 "{300E4533-FBD2-44B3-BED6-E656FF52E20D}"= Disabled:UDP:7289:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7289 "{E6D88E95-3619-4618-ACDC-C6E570999B10}"= Disabled:UDP:7290:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7290 "{6A9EF052-1FC4-4048-9A0C-D71CF0A91DD5}"= Disabled:UDP:7291:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7291 "{2EC834E0-A318-4E7A-934D-DCE7F99AAEE3}"= Disabled:UDP:7292:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7292 "{F0C2ADCD-027F-4F83-ABCD-DED4E6998E14}"= Disabled:UDP:7293:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7293 "{C788FA07-7765-438F-816D-BBC57A7AD7CA}"= Disabled:UDP:7294:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7294 "{0DE58F16-EF68-4037-9D81-9E8D332C4B40}"= Disabled:UDP:7295:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7295 "{618D88A4-B71A-4619-BD24-7A172B16BBA2}"= Disabled:UDP:7296:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7296 "{3B684CB2-6380-4B11-9DAA-203686A7F59D}"= Disabled:UDP:7297:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7297 "TCP Query User{A87CEF39-79F4-495B-8107-2669E9317E71}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire "UDP Query User{C0BCEEE4-5CBC-45C4-9A2A-9252EA89B6D7}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire "{4AA631F1-8A10-43E2-9AF2-50D523F7D8A6}"= Disabled:UDP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM "{BDB164A7-08E7-4FA3-9D14-411918B25E43}"= Disabled:TCP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM "TCP Query User{5047A0F9-65E8-4010-8166-8989AFB9EA7F}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire "UDP Query User{B8039892-6D92-4996-97E1-DB2E32B9868D}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire "{C0B7971A-92C6-49CF-A26F-4CBF0E92884B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In) "{D11DFF62-E2DF-493F-AA1A-9D220AA03955}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In) "{51757B52-543D-4D42-8D03-3396B16501C9}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{4A5BF50F-E211-4466-B638-2CFDFED791D1}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader "{2AFD8F0A-EDC7-4EE6-9448-5B1ACF10122F}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™ "{DEF7D8E2-E21B-4CB6-8115-9C934F821867}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™ "{D6F2FD21-59B8-4910-97E1-408F11257E50}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™ "{04F7FCF0-DE92-40FB-B775-20035D39BC7B}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™ "TCP Query User{B6388C41-AF36-4F37-A349-A603E91640B9}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:UDP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger "UDP Query User{2A133730-1F9C-4727-97CF-AFB8FCF73C83}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:TCP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger "{C9D98063-9DE5-4EDD-8E0B-603BCDA3233E}"= UDP:5353:Adobe CSI CS4 "{80F6A506-94F0-4270-8C5F-44268DC3201D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4 "{A8FDCCFA-B108-4263-9641-B5DEA85D487C}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4 "{0D423FB4-7220-4832-847B-0E85A9DD15AF}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{A1422C01-5FDB-4506-A2CB-3B046706FC5A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{29EE3451-05EE-47AF-8947-99DD5BFC854B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{F87D848E-3DA4-403D-BDDB-CFDE631A1128}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "{10B415ED-2A06-4C2F-9380-57B542D4FD1A}"= UDP:c:\program files\AIM6\aim6.exe:AIM "{3000B06D-2401-4D80-8E9F-6CE6751BEB6F}"= TCP:c:\program files\AIM6\aim6.exe:AIM "{BF7203B0-6B85-434C-9FCD-6188A11831B7}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) R2 gupdate1c9eba4d5aabe4e;Google Update Service (gupdate1c9eba4d5aabe4e);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 133104] R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888] R3 ControlTransferDriver;AudioBox USB Control Transfer;c:\windows\system32\Drivers\PreSonusUsb_xfer.sys [2008-02-18 28576] R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2006-11-23 18432] S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090715.003\IDSvix86.sys [2009-02-09 272432] S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;c:\windows\system32\libusbd-nt.exe [2005-03-10 18944] S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352] S2 musm3gld;musm3gld;c:\windows\system32\drivers\musm3gld.sys [2006-02-24 5513] S2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe [2007-03-21 548488] S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652] S2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-13 101936] S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-03-10 33792] S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2009-02-19 41008] — Other Services/Drivers In Memory — *NewlyCreated* - COMHOST [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28] 2009-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28] 2009-07-17 c:\windows\Tasks\User_Feed_Synchronization-{16669BE4-D9F0-4EB3-8A0B-146FE0D8BE1D}.job - c:\windows\system32\msfeedssync.exe [2009-07-02 11:31] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5070208 uInternet Settings,ProxyOverride = *.local IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab FF - ProfilePath - c:\users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\27qgbx4k.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;= FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} . ************************************************************************** scanning hidden processes … [0] 0x7004701A scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . Completion time: 2009-07-17 19:00 ComboFix-quarantined-files.txt 2009-07-17 23:00 ComboFix2.txt 2009-07-13 08:48 ComboFix3.txt 2009-07-13 08:23 ComboFix4.txt 2009-07-12 23:06 Pre-Run: 1,146,839,040 bytes free Post-Run: 2,156,380,160 bytes free 482 — E O F — 2009-07-17 05:02
I aslso noticed that in my windows defender that i had two quarentined items. I have the optoin to remove all ut i was wondering if i should or not:

Trojan:Win32/vuendo.gen!N

details:

Category:
Trojan

Description:
This program displays advertisements and may be difficult to remove.

Advice:
Remove this software immediately.

Resources:
file:
C:\Users\Robert\AppData\Local\Temp\aephqanb.dll

file:
C:\Users\Robert\AppData\Local\Temp\bkmjmwke.dll

file:
C:\Users\Robert\AppData\Local\Temp\nxesghnk.dll

file:
C:\Users\Robert\AppData\Local\Temp\syjghoyn.dll

file:
C:\Users\Robert\AppData\Local\Temp\ttvjvrry.dll

file:
C:\Users\Robert\AppData\Local\Temp\vtUklIBr.dll

file:
C:\Users\Robert\AppData\Local\Temp\wllmbuvu.dll

file:
C:\Users\Robert\AppData\Local\Temp\yhsmhtgf.dll

file:
C:\Users\Robert\AppData\Local\Temp\yxboaupw.dll

runkey:
HKCU@S-1-5-21-1592213791-1963367186-16139517-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\BMfdfd17ba

runkey:
HKCU@S-1-5-21-1592213791-1963367186-16139517-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\cmds

runkey:
HKCU@S-1-5-21-1592213791-1963367186-16139517-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\fece2426

regkey:
HKCU@S-1-5-21-1592213791-1963367186-16139517-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\BMfdfd17ba

regkey:
HKCU@S-1-5-21-1592213791-1963367186-16139517-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\cmds

regkey:
HKCU@S-1-5-21-1592213791-1963367186-16139517-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\fece2426

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{0BA28F37-0E62-44D9-8D7F-C650A00635E8}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{13F6DF4D-2593-4D9A-9D7B-DD88ECB15073}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{14653A8E-2885-4E9F-B049-6E0D1C6F9463}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{1965EEAB-5785-4CD8-8C40-0496C7CFD6D9}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{248C75E0-D583-4655-9797-CDAC246A6398}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{250d48f2-91ae-4e2e-9cf1-84817dde964d}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{30F9D10A-E287-4507-99B6-837F3901FA14}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{3104D679-4B9B-4E51-9069-606752941129}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{37fa84f4-ee1d-40e0-9f3a-0549194b3756}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{421a736f-0a7e-4246-a574-b0f6f3fb623b}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{45F5F72A-64F9-4A5B-A448-E938EC123CDC}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{69863A32-BAE4-4978-9AA3-C13C4067655D}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{69FDCA5A-DE5A-4D57-A882-9255E5F02304}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{73E8307F-1A86-4E6E-8A8D-93E9D7A1A445}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{7A33212E-4253-4692-B4AA-61A03E3EAC01}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{7B162CB1-F052-41BB-A1C5-D390E3214151}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{8330515a-9230-4e93-8ca0-d9d28a9d530d}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{95FAAE93-5C75-4224-B013-5290E67461DE}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{A5BD9632-3752-47F2-97F6-EB2AA38D5EBA}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{AA2EDD07-690D-4656-89D9-E754D5C9F09D}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{AE753DFB-F365-4DC0-91C1-B7CEE12E85E5}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{B9144AA7-8928-4768-86F0-4D3A0345CCF2}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{D243E76E-6682-4FC4-9BAB-16902EB1E572}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{d712a5c5-5d5d-428c-8b82-d3aa811acc6c}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{efb0b79d-6fe7-464c-8f34-c0586e26efb6}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{F99CCE45-5AE8-4792-8787-55290F97987F}

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{FA637CB2-5FB6-4E97-9571-3D43260F0874}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{0BA28F37-0E62-44D9-8D7F-C650A00635E8}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{13F6DF4D-2593-4D9A-9D7B-DD88ECB15073}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{14653A8E-2885-4E9F-B049-6E0D1C6F9463}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{1965EEAB-5785-4CD8-8C40-0496C7CFD6D9}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{248C75E0-D583-4655-9797-CDAC246A6398}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{250d48f2-91ae-4e2e-9cf1-84817dde964d}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{30F9D10A-E287-4507-99B6-837F3901FA14}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{3104D679-4B9B-4E51-9069-606752941129}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{37fa84f4-ee1d-40e0-9f3a-0549194b3756}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{421a736f-0a7e-4246-a574-b0f6f3fb623b}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{45F5F72A-64F9-4A5B-A448-E938EC123CDC}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{69863A32-BAE4-4978-9AA3-C13C4067655D}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{69FDCA5A-DE5A-4D57-A882-9255E5F02304}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{73E8307F-1A86-4E6E-8A8D-93E9D7A1A445}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{7A33212E-4253-4692-B4AA-61A03E3EAC01}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{7B162CB1-F052-41BB-A1C5-D390E3214151}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{8330515a-9230-4e93-8ca0-d9d28a9d530d}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{95FAAE93-5C75-4224-B013-5290E67461DE}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{A5BD9632-3752-47F2-97F6-EB2AA38D5EBA}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{AA2EDD07-690D-4656-89D9-E754D5C9F09D}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{AE753DFB-F365-4DC0-91C1-B7CEE12E85E5}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{B9144AA7-8928-4768-86F0-4D3A0345CCF2}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{D243E76E-6682-4FC4-9BAB-16902EB1E572}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{d712a5c5-5d5d-428c-8b82-d3aa811acc6c}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{efb0b79d-6fe7-464c-8f34-c0586e26efb6}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{F99CCE45-5AE8-4792-8787-55290F97987F}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{FA637CB2-5FB6-4E97-9571-3D43260F0874}

View more information about this item online



And trojan:win32/vuendo.gen!M


details:

Category:
Trojan

Description:
This program displays advertisements and may be difficult to remove.

Advice:
Remove this software immediately.

Resources:
file:
C:\Users\Robert\AppData\Local\Temp\geButQhG.dll

runkey:
HKCU@S-1-5-21-1592213791-1963367186-16139517-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\MSServer

regkey:
HKCU@S-1-5-21-1592213791-1963367186-16139517-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\MSServer

regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{8710FC9F-0816-49D7-AE14-4BA5269E838C}

clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{8710FC9F-0816-49D7-AE14-4BA5269E838C}

View more information about this item online
Yes, do remove all of those in quarentine.

Congratulations, you are now all clean! To help to prevent from becoming reinfected, please follow the instructions below in order. If you have any questions, please feel free to ask them. If after 48 hours you have not responded to this, then I will assume you have no questions and have the topic closed.

First, lets uninstall ComboFix:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


Flush the system restore points

  • Right click on My Computer and select Properties.
  • Select the System Restore tab.
  • Check (tick) Turn off system restore on all drives box.
  • Click Apply.
  • Uncheck (untick) Turn off system restore on all drives box.
  • Click OK.
  • Restart your computer.
Note: Do this only ONCE, don't flush it regularly.

Keep your system updated

Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Please ensure that you visit the following websites regularly or do update your system regularly.

Install the updates immediately if they are found. Reboot your computer if necessary, revisit Windows Update and Office update sites until there are no more updates to be installed.

To update Windows and office

Go to Start > All Programs > Microsoft Update


Alternatively, you can visit the link below to update Windows and Office products.

Microsoft Update

I also recommend, if it's not already on, to enable Automatic updates. It will notify you whenever there are new updates available. Here's how:

  • Go to Start > Control Panel > Automatic Updates
  • Select Automatic (recommended) radio button if you want the updates to be downloaded and installed without prompting you.
  • Select Download updates for me, but let me chose when to install them radio button if you want the updates to be downloaded automatically but to be installed at another time.
  • Select Notify me but don't automatically download or install them radio button if you want to be notified of the updates.

Besides Windows that needs regular updating, antivirus, anti-spyware and firewall programs update regularly too.

Please make sure that you update your antivirus, firewall and anti-spyware programs at least once a week.

Surf safely

Many of the exploits are directed to users of Internet Explorer and Firefox.

Using Firefox with NoScript add-on helps to prevent most exploits from running as NoScript by default disables all scripts on all websites. If you trust the website, you can manually allow it.

Backup regularly

You never know when your PC will become unstable or become so infected that you can't recover it. Follow this Microsoft article to learn how to backup. Follow this article by Microsoft to restore your backups.

Alternatively, you can use 3rd-party programs to back up your data. One example can be found at Bleeping Computer.

Avoid P2P

P2P may be a great way to get lots of stuffs, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well. If you do need to use them, use them sparingly. Check this list of clean and infected P2P programs if you need to use one.

Prevent a re-infection

  • Winpatrol
    Winpatrol is heuristic protection program, meaning it looks for patterns in codes that work like malware. It also takes a snapshot of your system's critical resources and alerts you to any changes that may occur without you knowing. You can read more about Winpatrol's features here.

    You can get a free copy of Winpatrol or use the Plus version for more features.

    You can read Winpatrol's FAQ if you run into problems.

  • Hosts File
    A Hosts file is like a phone book. You look up someone's name in the phone book before calling him/her. Similarly, your PC will look up the website's IP address before you can view the website.

    Hosts file will replace your current Hosts file with another one containing well-known advertisement sites, spyware sites and other bad sites. This new Hosts file will protect you by re-directing these bad sites to 127.0.0.1.

    Here are some Hosts files:

    MVPS Hosts File
    Bluetack's Hosts File
    Bluetack's Host Manager
    hpHosts

    A tutorial about Hosts File can be found at Malware Removal.

  • Spybot Search and Destroy
    Spybot Search & Destroy is another program for scanning spywares and adwares. Not only so, it has other preventive options as well. You are strongly encouraged to run a scan at least once per week.

    Spybot Search & Destroy can be downloaded from here.

    If you need help in using Spybot Search & Destroy, you can read Spybot Search and Destroy tutorial at Bleeping Computer.

    Before downloading any anti-spyware programs, always check the Rogue/Suspect list of anti-spyware programs and Malwarebytes RogueNET. This will save you from a lot of trouble. If in doubt, don't ever download it.

  • SiteHound Toolbar
    SiteHound is a toolbar that warns you if you go to a site that is known to scam people, that has potentially lots of viruses or spywares or has questionable contents. If you know the site, you can enter it; if you don't, it will bring you back to the previous page. Currently, SiteHound works for Internet Explorer and Firefox only.


Stand Up and Be Counted —> Malware Complaints <— where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Happy surfing and stay clean!

Regards,
Adam
Hey i wanted to have you check the home pc at my house is it ok to place the log in this post. Its just extremely slow my mom does alot of nonsense on it and our guests always use it. Also check your paypal. When i get more il continue to donate.
Please start a new topic for your mom's computer or any other computer at that.

Thanks you, the donation is much appreciated. :)

I'm sorry, I forgot to add this to my previous post:

  • Please double-click OTM.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Click the CleanUp! button.
  • When it prompts you to Restart, click Yes.

I recommend keeping MBAM though, and scanning with it periodically. If you do want to remove MBAM, it can be done from Add/Remove programs.

REgards,
Adam
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI