[Resolved] http://error404.index.com or http://error404.com/ after an
88 min read
Download Deldomains.
- Save it to your desktop.
- Right-click DelDomains.inf and select: Install (no need to restart)
- You may not see any noticeable changes or prompts; this is normal.
Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
- Double click on ComboFix.exe & follow the prompts.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
[external image: Posted Image]
- Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
- Click on Yes, to continue scanning for malware.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
also u told me this: 'You will have to re-immunize with SpywareBlaster, and/or Spybot after doing this, and reinstall IESpyads if you use any of these programs."
do i have to wait for your instruction or that u send me the link.? and if i download them, will they cause trouble with my mcafee security system (like having 2 antiviruses working together?)
*** forgot to mention: i still have the viruses from that day in my mcafee as quarantined… what should i do with them??
file names:
INCOSNET.TMP (A KIND OF ARTEMIS)
MACCSNET.TMP (A KIND OF ARTEMIS)
RASESNET.TMP (A KIND OF ARTEMIS)
SMCONWERXA.EXE (A KIND OF ARTEMIS)
SPOOL.EXE (A KIND OF GENERIC)
XPRE.TMP (A KIND OF GENERIC)
thnx for your help SweetTech
ComboFix 09-11-20.05 - Latisnere 11/21/2009 10:30.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1958 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2885513011-442255764-2486443271-500
c:\users\Latisnere\AppData\Local\Microsoft\Windows\Temporary Internet Files\TestBrowser.html
c:\users\Latisnere\AppData\Roaming\inst.exe
.
((((((((((((((((((((((((( Files Created from 2009-10-21 to 2009-11-21 )))))))))))))))))))))))))))))))
.
2009-11-21 16:39 . 2009-11-21 16:39 ——– d—–w- c:\users\Latisnere\AppData\Local\temp
2009-11-21 16:39 . 2009-11-21 16:39 ——– d—–w- c:\users\Mcx2\AppData\Local\temp
2009-11-21 16:39 . 2009-11-21 16:39 ——– d—–w- c:\users\Mcx1\AppData\Local\temp
2009-11-21 16:39 . 2009-11-21 16:39 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-11-18 18:19 . 2009-11-18 18:19 4096 d—–w- c:\program files\ERUNT
2009-11-18 17:27 . 2009-11-18 17:27 ——– d—–w- c:\programdata\Citrix
2009-11-18 17:23 . 2009-11-18 17:23 ——– d—–w- c:\program files\Citrix
2009-11-18 17:23 . 2009-11-18 17:23 ——– d—–w- c:\users\Latisnere\AppData\Local\Citrix
2009-11-18 17:23 . 2009-11-18 17:23 61224 —-a-w- c:\users\Latisnere\GoToAssistDownloadHelper.exe
2009-11-18 02:03 . 2009-11-18 02:03 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-18 02:00 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2009-11-18 02:00 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2009-11-18 02:00 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2009-11-18 01:57 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-11-18 01:57 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-18 01:57 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-11-18 01:47 . 2009-08-29 00:14 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2009-11-18 01:47 . 2009-08-29 00:27 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-11-18 01:47 . 2009-08-14 13:27 2036736 —-a-w- c:\windows\system32\win32k.sys
2009-11-18 01:47 . 2009-09-10 14:58 310784 —-a-w- c:\windows\system32\unregmp2.exe
2009-11-18 01:47 . 2009-09-10 14:59 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-11-18 01:44 . 2009-08-10 12:35 355328 —-a-w- c:\windows\system32\WSDApi.dll
2009-11-18 01:38 . 2009-11-18 01:38 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-18 01:27 . 2009-11-18 01:27 ——– d—–w- c:\users\Latisnere\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-11-18 01:26 . 2009-11-18 01:26 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-18 01:23 . 2009-10-10 07:07 38208 —-a-w- c:\users\Latisnere\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-18 01:23 . 2009-11-18 01:23 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-11-18 01:23 . 2009-10-10 07:07 38208 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-18 01:12 . 2009-11-18 01:12 ——– d—–w- c:\programdata\McAfee Security Scan
2009-11-18 01:12 . 2009-11-18 01:12 ——– d—–w- c:\program files\McAfee Security Scan
2009-11-18 01:12 . 2009-11-18 01:12 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2009-11-18 01:11 . 2009-11-18 01:29 4096 d—–w- c:\programdata\NOS
2009-11-18 01:10 . 2009-11-06 15:20 34112 —-a-w- c:\users\Latisnere\AppData\Roaming\Mozilla\Firefox\Profiles\xtqgsnxv.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-18 01:10 . 2009-11-06 15:20 22352 —-a-w- c:\users\Latisnere\AppData\Roaming\Mozilla\Firefox\Profiles\xtqgsnxv.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-11-16 23:43 . 2009-11-16 23:43 8240064 —-a-w- c:\users\Latisnere\AppData\Roaming\Azureus\tmp\AZU4854.tmp\Vuze_4.3.0.0_win32.exe
2009-11-10 07:10 . 2006-11-29 19:06 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2009-11-10 07:09 . 2009-11-10 07:09 ——– d—–w- c:\program files\Microsoft
2009-11-10 05:17 . 2009-11-10 05:17 ——– d—–w- c:\programdata\Defence
2009-11-10 05:17 . 2009-11-09 22:26 24064 —-a-w- c:\programdata\Defence\smss.exe
2009-11-08 01:28 . 2009-11-08 01:28 ——– d—–w- c:\users\Latisnere\AppData\Roaming\Intel
2009-11-04 02:09 . 2009-11-04 02:33 ——– d—–w- c:\users\Latisnere\AppData\Roaming\ImgBurn
2009-11-04 02:08 . 2009-11-04 02:08 4096 d—–w- c:\program files\ImgBurn
2009-11-02 09:13 . 2009-11-07 03:29 4096 d—–w- c:\users\Latisnere\AppData\Roaming\uTorrent
2009-11-02 08:46 . 2009-11-02 08:47 12288 d—–w- c:\program files\WeFi
2009-11-02 08:44 . 2009-11-02 08:45 4096 d—–w- c:\program files\Vuze
2009-11-01 22:43 . 2009-11-01 22:43 4096 d—–w- c:\program files\abgx360
2009-10-27 03:16 . 2009-08-07 02:24 44768 —-a-w- c:\windows\system32\wups2.dll
2009-10-27 03:16 . 2009-08-07 02:24 53472 —-a-w- c:\windows\system32\wuauclt.exe
2009-10-27 03:16 . 2009-08-07 01:45 2421760 —-a-w- c:\windows\system32\wucltux.dll
2009-10-27 03:16 . 2009-08-07 02:23 1929952 —-a-w- c:\windows\system32\wuaueng.dll
2009-10-27 03:16 . 2009-08-07 02:24 35552 —-a-w- c:\windows\system32\wups.dll
2009-10-27 03:16 . 2009-08-07 02:23 575704 —-a-w- c:\windows\system32\wuapi.dll
2009-10-27 03:16 . 2009-08-07 01:44 87552 —-a-w- c:\windows\system32\wudriver.dll
2009-10-27 03:16 . 2009-08-07 00:23 171608 —-a-w- c:\windows\system32\wuwebv.dll
2009-10-27 03:16 . 2009-08-06 23:44 33792 —-a-w- c:\windows\system32\wuapp.exe
2009-10-25 23:58 . 2009-10-29 05:09 179 —-a-w- c:\users\Latisnere\AppData\Roaming\Azureus\restart.bat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 16:04 . 2009-07-23 07:38 119887 —-a-w- c:\programdata\nvModes.dat
2009-11-21 16:04 . 2008-10-28 14:51 4096 d—–w- c:\programdata\Sonic
2009-11-21 10:09 . 2009-08-16 05:29 12 —-a-w- c:\windows\bthservsdp.dat
2009-11-20 18:54 . 2009-07-24 08:31 4096 d—–w- c:\program files\McAfee
2009-11-19 04:29 . 2009-09-16 21:12 4096 d—–w- c:\users\Latisnere\AppData\Roaming\Skype
2009-11-19 04:16 . 2009-09-16 21:14 4096 d—–w- c:\users\Latisnere\AppData\Roaming\skypePM
2009-11-18 02:07 . 2008-10-28 15:02 ——– d—–w- c:\programdata\NVIDIA
2009-11-18 02:03 . 2006-11-02 11:18 4096 d—–w- c:\program files\Windows Mail
2009-11-18 02:03 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 02:03 . 2009-11-18 02:03 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 02:03 . 2009-11-18 02:03 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-18 01:38 . 2008-10-28 14:42 ——– d—–w- c:\program files\Java
2009-11-18 01:18 . 2008-10-28 14:52 4096 d—–w- c:\programdata\Roxio
2009-11-16 23:43 . 2009-07-25 03:33 20480 d—–w- c:\users\Latisnere\AppData\Roaming\Azureus
2009-11-10 07:11 . 2008-10-28 14:44 4096 d—–w- c:\program files\Windows Live
2009-10-29 05:09 . 2009-08-03 02:31 6516755 —-a-w- c:\users\Latisnere\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe
2009-10-29 05:09 . 2009-08-03 02:31 4141117 —-a-w- c:\users\Latisnere\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe
2009-10-19 22:16 . 2009-07-25 03:32 4096 d—–w- c:\program files\Microsoft Silverlight
2009-10-18 09:57 . 2009-07-23 07:42 ——– d—–w- c:\users\Latisnere\AppData\Roaming\Creative
2009-10-15 05:32 . 2009-07-24 05:33 4096 d—–w- c:\users\Latisnere\AppData\Roaming\Vso
2009-10-10 07:07 . 2009-11-20 09:07 38208 —-a-w- c:\users\Mcx2\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-01 01:02 . 2009-11-18 01:59 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-11-18 01:59 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-11-18 01:59 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-11-18 01:59 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-11-18 01:59 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-11-18 01:59 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-11-18 01:59 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-11-18 01:59 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-11-18 01:59 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-11-18 01:59 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-11-18 01:59 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-11-18 01:59 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-11-18 01:59 40448 —-a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-11-18 01:59 226816 —-a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-11-18 01:59 61952 —-a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-11-18 01:59 33280 —-a-w- c:\windows\system32\WpdConns.dll
2009-09-25 02:10 . 2009-11-18 01:59 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-18 01:59 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-18 01:59 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-18 01:59 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-18 01:59 351232 —-a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-18 01:59 847360 —-a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-18 01:59 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-18 01:59 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-18 01:59 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-18 01:59 829440 —-a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-18 01:59 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-18 01:59 252928 —-a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-18 01:59 519680 —-a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-18 01:59 486912 —-a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-18 01:59 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-18 01:59 218112 —-a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-18 01:59 1030144 —-a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-18 01:59 828928 —-a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-18 01:59 481792 —-a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-18 01:59 190464 —-a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-18 01:59 634880 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-18 01:59 37888 —-a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-18 01:59 793088 —-a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-18 01:59 1064448 —-a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-11-18 01:59 258048 —-a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-11-18 01:59 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-11-18 01:59 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-23 03:51 . 2009-07-23 09:12 4096 d—–w- c:\users\Latisnere\AppData\Roaming\Roxio
2009-09-16 21:14 . 2009-09-16 21:14 56 —ha-w- c:\programdata\ezsidmv.dat
2009-09-16 15:22 . 2009-07-24 08:31 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 15:22 . 2009-07-24 08:31 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 15:22 . 2009-07-24 08:31 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 15:22 . 2009-05-14 04:25 214664 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 15:22 . 2009-07-24 08:26 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-14 09:29 . 2009-10-19 22:02 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 16:48 . 2009-10-19 22:02 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-04 11:41 . 2009-10-19 22:00 60928 —-a-w- c:\windows\system32\msasn1.dll
2009-08-27 05:22 . 2009-10-19 22:04 916480 —-a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-19 22:04 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-19 22:04 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-19 22:04 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2008-10-27 20:39 . 2008-10-27 20:08 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-17 04:13 721408 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-17 04:13 721408 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Defence"="c:\programdata\Defence\smss.exe" [2009-11-09 24064]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-07 159744]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-28 36864]
"VolPanel"="c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-27 180224]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"PSQLLauncher"="c:\program files\Fingerprint Reader Suite\launcher.exe" [2007-04-17 49168]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe" [2008-08-14 240112]
"CPMonitor"="c:\program files\Roxio Creator 2009\5.0\CPMonitor.exe" [2008-08-10 80368]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-12-03 405504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-18 149280]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-16 13793824]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2009-06-16 92704]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-17 04:04 86528 —-a-w- c:\windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [10/28/2008 8:29 AM 73728]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [7/24/2009 2:32 AM 210216]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [10/10/2007 4:03 PM 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [10/27/2008 2:53 PM 7424]
S2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe [8/13/2008 11:25 PM 367088]
S2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [8/13/2008 11:24 PM 309744]
S2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [8/13/2008 11:24 PM 170480]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [7/24/2009 12:07 AM 21504]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [8/13/2008 11:25 PM 313840]
S3 RoxMediaDB11;RoxMediaDB11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [8/13/2008 11:23 PM 1124848]
S4 iaNvStor;Intel® Turbo Memory Controller;c:\windows\System32\drivers\iaNvStor.sys [10/27/2008 2:53 PM 209408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2009-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 17:22]
2009-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 17:22]
2009-11-20 c:\windows\Tasks\User_Feed_Synchronization-{C81409E6-6B7F-4F66-B9D0-D19D7E8AC5B5}.job
- c:\windows\system32\msfeedssync.exe [2009-10-19 03:41]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p;=%s
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Latisnere\AppData\Roaming\Mozilla\Firefox\Profiles\xtqgsnxv.default\
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10607&gct;=&gc;=1&q;=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Lsass Service - c:\users\Latisnere\AppData\Roaming\Microsoft\Windows\lsass.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-21 10:39
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Lsass Service = c:\users\Latisnere\AppData\Roaming\Microsoft\Windows\lsass.exe??N??????????????????????????????????? ???????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(692)
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll
.
Completion time: 2009-11-21 10:44
ComboFix-quarantined-files.txt 2009-11-21 16:44
Pre-Run: 95,721,533,440 bytes free
Post-Run: 95,682,220,032 bytes free
- - End Of File - - AF4B7434A7356C92E8B02B2B5C430911
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
- They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')
http://forums.whatthetech.com/http_error404_index_com_http_error404_com_after_attack_t108354.html&view=findpost&p=612461#entry612461 KillAll:: Collect:: c:\programdata\Defence\smss.exe Folder:: c:\programdata\Defence Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Defence"=- FileLook:: c:\users\Latisnere\AppData\Roaming\Azureus\restart.bat Rootkit:: c:\users\Latisnere\AppData\Roaming\Microsoft\Windows\lsass.exe
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you.
- Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
- Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan - Click the [external image: Posted Image] button.
- For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
- Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
- Double click on the [external image: Posted Image] icon on your desktop.
- Check [external image: Posted Image]
- Click the [external image: Posted Image] button.
- Accept any security warnings from your browser.
- Check [external image: Posted Image]
- Make sure that the option "Remove found threats" is Unchecked
- Push the Start button.
- ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time. - When the scan completes, push [external image: Posted Image]
- Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply. - Push the [external image: Posted Image] button.
- Push [external image: Posted Image]
1. The log that was produced after running ComboFix.
2. The log that was produced after running MalwareBytes' Anti-Malware.
3. The log that was produced after running ESET Online Scanner.
4. An update on how your computer is currently running?
Please do the following:
- Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
- Click on Explore
- Click on Local Disk (C:) in the left-hand window pane
- Look for ComboFix.txt in the right-hand window pane and right click on it
- Put your cursor (arrow) on Open With
- Move your cursor to the new menu that opens and click on Choose Program…
- Click on Notepad
When file opens, Copy/Paste text here
again i apologize
ComboFix 09-11-20.05 - Latisnere 11/21/2009 10:30.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1958 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2885513011-442255764-2486443271-500
c:\users\Latisnere\AppData\Local\Microsoft\Windows\Temporary Internet Files\TestBrowser.html
c:\users\Latisnere\AppData\Roaming\inst.exe
.
((((((((((((((((((((((((( Files Created from 2009-10-21 to 2009-11-21 )))))))))))))))))))))))))))))))
.
2009-11-21 16:39 . 2009-11-21 16:39 ——– d—–w- c:\users\Latisnere\AppData\Local\temp
2009-11-21 16:39 . 2009-11-21 16:39 ——– d—–w- c:\users\Mcx2\AppData\Local\temp
2009-11-21 16:39 . 2009-11-21 16:39 ——– d—–w- c:\users\Mcx1\AppData\Local\temp
2009-11-21 16:39 . 2009-11-21 16:39 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-11-18 18:19 . 2009-11-18 18:19 4096 d—–w- c:\program files\ERUNT
2009-11-18 17:27 . 2009-11-18 17:27 ——– d—–w- c:\programdata\Citrix
2009-11-18 17:23 . 2009-11-18 17:23 ——– d—–w- c:\program files\Citrix
2009-11-18 17:23 . 2009-11-18 17:23 ——– d—–w- c:\users\Latisnere\AppData\Local\Citrix
2009-11-18 17:23 . 2009-11-18 17:23 61224 —-a-w- c:\users\Latisnere\GoToAssistDownloadHelper.exe
2009-11-18 02:03 . 2009-11-18 02:03 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-18 02:00 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2009-11-18 02:00 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2009-11-18 02:00 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2009-11-18 01:57 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-11-18 01:57 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-18 01:57 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-11-18 01:47 . 2009-08-29 00:14 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2009-11-18 01:47 . 2009-08-29 00:27 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-11-18 01:47 . 2009-08-14 13:27 2036736 —-a-w- c:\windows\system32\win32k.sys
2009-11-18 01:47 . 2009-09-10 14:58 310784 —-a-w- c:\windows\system32\unregmp2.exe
2009-11-18 01:47 . 2009-09-10 14:59 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-11-18 01:44 . 2009-08-10 12:35 355328 —-a-w- c:\windows\system32\WSDApi.dll
2009-11-18 01:38 . 2009-11-18 01:38 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-18 01:27 . 2009-11-18 01:27 ——– d—–w- c:\users\Latisnere\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-11-18 01:26 . 2009-11-18 01:26 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-18 01:23 . 2009-10-10 07:07 38208 —-a-w- c:\users\Latisnere\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-18 01:23 . 2009-11-18 01:23 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-11-18 01:23 . 2009-10-10 07:07 38208 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-18 01:12 . 2009-11-18 01:12 ——– d—–w- c:\programdata\McAfee Security Scan
2009-11-18 01:12 . 2009-11-18 01:12 ——– d—–w- c:\program files\McAfee Security Scan
2009-11-18 01:12 . 2009-11-18 01:12 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2009-11-18 01:11 . 2009-11-18 01:29 4096 d—–w- c:\programdata\NOS
2009-11-18 01:10 . 2009-11-06 15:20 34112 —-a-w- c:\users\Latisnere\AppData\Roaming\Mozilla\Firefox\Profiles\xtqgsnxv.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-18 01:10 . 2009-11-06 15:20 22352 —-a-w- c:\users\Latisnere\AppData\Roaming\Mozilla\Firefox\Profiles\xtqgsnxv.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-11-16 23:43 . 2009-11-16 23:43 8240064 —-a-w- c:\users\Latisnere\AppData\Roaming\Azureus\tmp\AZU4854.tmp\Vuze_4.3.0.0_win32.exe
2009-11-10 07:10 . 2006-11-29 19:06 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2009-11-10 07:09 . 2009-11-10 07:09 ——– d—–w- c:\program files\Microsoft
2009-11-10 05:17 . 2009-11-10 05:17 ——– d—–w- c:\programdata\Defence
2009-11-10 05:17 . 2009-11-09 22:26 24064 —-a-w- c:\programdata\Defence\smss.exe
2009-11-08 01:28 . 2009-11-08 01:28 ——– d—–w- c:\users\Latisnere\AppData\Roaming\Intel
2009-11-04 02:09 . 2009-11-04 02:33 ——– d—–w- c:\users\Latisnere\AppData\Roaming\ImgBurn
2009-11-04 02:08 . 2009-11-04 02:08 4096 d—–w- c:\program files\ImgBurn
2009-11-02 09:13 . 2009-11-07 03:29 4096 d—–w- c:\users\Latisnere\AppData\Roaming\uTorrent
2009-11-02 08:46 . 2009-11-02 08:47 12288 d—–w- c:\program files\WeFi
2009-11-02 08:44 . 2009-11-02 08:45 4096 d—–w- c:\program files\Vuze
2009-11-01 22:43 . 2009-11-01 22:43 4096 d—–w- c:\program files\abgx360
2009-10-27 03:16 . 2009-08-07 02:24 44768 —-a-w- c:\windows\system32\wups2.dll
2009-10-27 03:16 . 2009-08-07 02:24 53472 —-a-w- c:\windows\system32\wuauclt.exe
2009-10-27 03:16 . 2009-08-07 01:45 2421760 —-a-w- c:\windows\system32\wucltux.dll
2009-10-27 03:16 . 2009-08-07 02:23 1929952 —-a-w- c:\windows\system32\wuaueng.dll
2009-10-27 03:16 . 2009-08-07 02:24 35552 —-a-w- c:\windows\system32\wups.dll
2009-10-27 03:16 . 2009-08-07 02:23 575704 —-a-w- c:\windows\system32\wuapi.dll
2009-10-27 03:16 . 2009-08-07 01:44 87552 —-a-w- c:\windows\system32\wudriver.dll
2009-10-27 03:16 . 2009-08-07 00:23 171608 —-a-w- c:\windows\system32\wuwebv.dll
2009-10-27 03:16 . 2009-08-06 23:44 33792 —-a-w- c:\windows\system32\wuapp.exe
2009-10-25 23:58 . 2009-10-29 05:09 179 —-a-w- c:\users\Latisnere\AppData\Roaming\Azureus\restart.bat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 16:04 . 2009-07-23 07:38 119887 —-a-w- c:\programdata\nvModes.dat
2009-11-21 16:04 . 2008-10-28 14:51 4096 d—–w- c:\programdata\Sonic
2009-11-21 10:09 . 2009-08-16 05:29 12 —-a-w- c:\windows\bthservsdp.dat
2009-11-20 18:54 . 2009-07-24 08:31 4096 d—–w- c:\program files\McAfee
2009-11-19 04:29 . 2009-09-16 21:12 4096 d—–w- c:\users\Latisnere\AppData\Roaming\Skype
2009-11-19 04:16 . 2009-09-16 21:14 4096 d—–w- c:\users\Latisnere\AppData\Roaming\skypePM
2009-11-18 02:07 . 2008-10-28 15:02 ——– d—–w- c:\programdata\NVIDIA
2009-11-18 02:03 . 2006-11-02 11:18 4096 d—–w- c:\program files\Windows Mail
2009-11-18 02:03 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 02:03 . 2009-11-18 02:03 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 02:03 . 2009-11-18 02:03 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-18 01:38 . 2008-10-28 14:42 ——– d—–w- c:\program files\Java
2009-11-18 01:18 . 2008-10-28 14:52 4096 d—–w- c:\programdata\Roxio
2009-11-16 23:43 . 2009-07-25 03:33 20480 d—–w- c:\users\Latisnere\AppData\Roaming\Azureus
2009-11-10 07:11 . 2008-10-28 14:44 4096 d—–w- c:\program files\Windows Live
2009-10-29 05:09 . 2009-08-03 02:31 6516755 —-a-w- c:\users\Latisnere\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe
2009-10-29 05:09 . 2009-08-03 02:31 4141117 —-a-w- c:\users\Latisnere\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe
2009-10-19 22:16 . 2009-07-25 03:32 4096 d—–w- c:\program files\Microsoft Silverlight
2009-10-18 09:57 . 2009-07-23 07:42 ——– d—–w- c:\users\Latisnere\AppData\Roaming\Creative
2009-10-15 05:32 . 2009-07-24 05:33 4096 d—–w- c:\users\Latisnere\AppData\Roaming\Vso
2009-10-10 07:07 . 2009-11-20 09:07 38208 —-a-w- c:\users\Mcx2\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-01 01:02 . 2009-11-18 01:59 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-11-18 01:59 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-11-18 01:59 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-11-18 01:59 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-11-18 01:59 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-11-18 01:59 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-11-18 01:59 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-11-18 01:59 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-11-18 01:59 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-11-18 01:59 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-11-18 01:59 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-11-18 01:59 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-11-18 01:59 40448 —-a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-11-18 01:59 226816 —-a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-11-18 01:59 61952 —-a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-11-18 01:59 33280 —-a-w- c:\windows\system32\WpdConns.dll
2009-09-25 02:10 . 2009-11-18 01:59 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-18 01:59 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-18 01:59 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-18 01:59 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-18 01:59 351232 —-a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-18 01:59 847360 —-a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-18 01:59 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-18 01:59 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-18 01:59 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-18 01:59 829440 —-a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-18 01:59 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-18 01:59 252928 —-a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-18 01:59 519680 —-a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-18 01:59 486912 —-a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-18 01:59 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-18 01:59 218112 —-a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-18 01:59 1030144 —-a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-18 01:59 828928 —-a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-18 01:59 481792 —-a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-18 01:59 190464 —-a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-18 01:59 634880 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-18 01:59 37888 —-a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-18 01:59 793088 —-a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-18 01:59 1064448 —-a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-11-18 01:59 258048 —-a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-11-18 01:59 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-11-18 01:59 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-23 03:51 . 2009-07-23 09:12 4096 d—–w- c:\users\Latisnere\AppData\Roaming\Roxio
2009-09-16 21:14 . 2009-09-16 21:14 56 —ha-w- c:\programdata\ezsidmv.dat
2009-09-16 15:22 . 2009-07-24 08:31 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 15:22 . 2009-07-24 08:31 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 15:22 . 2009-07-24 08:31 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 15:22 . 2009-05-14 04:25 214664 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 15:22 . 2009-07-24 08:26 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-14 09:29 . 2009-10-19 22:02 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 16:48 . 2009-10-19 22:02 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-04 11:41 . 2009-10-19 22:00 60928 —-a-w- c:\windows\system32\msasn1.dll
2009-08-27 05:22 . 2009-10-19 22:04 916480 —-a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-19 22:04 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-19 22:04 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-19 22:04 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2008-10-27 20:39 . 2008-10-27 20:08 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-17 04:13 721408 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-17 04:13 721408 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Defence"="c:\programdata\Defence\smss.exe" [2009-11-09 24064]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-07 159744]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-28 36864]
"VolPanel"="c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-27 180224]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"PSQLLauncher"="c:\program files\Fingerprint Reader Suite\launcher.exe" [2007-04-17 49168]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe" [2008-08-14 240112]
"CPMonitor"="c:\program files\Roxio Creator 2009\5.0\CPMonitor.exe" [2008-08-10 80368]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-12-03 405504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-18 149280]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-16 13793824]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2009-06-16 92704]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-17 04:04 86528 —-a-w- c:\windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [10/28/2008 8:29 AM 73728]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [7/24/2009 2:32 AM 210216]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [10/10/2007 4:03 PM 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [10/27/2008 2:53 PM 7424]
S2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe [8/13/2008 11:25 PM 367088]
S2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [8/13/2008 11:24 PM 309744]
S2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [8/13/2008 11:24 PM 170480]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [7/24/2009 12:07 AM 21504]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [8/13/2008 11:25 PM 313840]
S3 RoxMediaDB11;RoxMediaDB11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [8/13/2008 11:23 PM 1124848]
S4 iaNvStor;Intel® Turbo Memory Controller;c:\windows\System32\drivers\iaNvStor.sys [10/27/2008 2:53 PM 209408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2009-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 17:22]
2009-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 17:22]
2009-11-20 c:\windows\Tasks\User_Feed_Synchronization-{C81409E6-6B7F-4F66-B9D0-D19D7E8AC5B5}.job
- c:\windows\system32\msfeedssync.exe [2009-10-19 03:41]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p;=%s
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Latisnere\AppData\Roaming\Mozilla\Firefox\Profiles\xtqgsnxv.default\
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10607&gct;=&gc;=1&q;=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Lsass Service - c:\users\Latisnere\AppData\Roaming\Microsoft\Windows\lsass.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-21 10:39
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Lsass Service = c:\users\Latisnere\AppData\Roaming\Microsoft\Windows\lsass.exe??N??????????????????????????????????? ???????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(692)
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll
.
Completion time: 2009-11-21 10:44
ComboFix-quarantined-files.txt 2009-11-21 16:44
Pre-Run: 95,721,533,440 bytes free
Post-Run: 95,682,220,032 bytes free
- - End Of File - - AF4B7434A7356C92E8B02B2B5C430911
It seems that something wacky happened. and the ComboFix script didn't work properly. I'd like for us to run the script again. But first lets delete the CFScript file on your desktop. Once you've deleted that file please proceed with the following:
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
- They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')
http://forums.whatthetech.com/http_error404_index_com_http_error404_com_after_attack_t108354.html&view=findpost&p=612461#entry612461 KillAll:: Collect:: c:\programdata\Defence\smss.exe Folder:: c:\programdata\Defence Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Defence"=- FileLook:: c:\users\Latisnere\AppData\Roaming\Azureus\restart.bat Rootkit:: c:\users\Latisnere\AppData\Roaming\Microsoft\Windows\lsass.exe
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you.
- Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
- Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan - Click the [external image: Posted Image] button.
- For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
- Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
- Double click on the [external image: Posted Image] icon on your desktop.
- Check [external image: Posted Image]
- Click the [external image: Posted Image] button.
- Accept any security warnings from your browser.
- Check [external image: Posted Image]
- Make sure that the option "Remove found threats" is Unchecked
- Push the Start button.
- ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time. - When the scan completes, push [external image: Posted Image]
- Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply. - Push the [external image: Posted Image] button.
- Push [external image: Posted Image]
1. The log that was produced after running ComboFix.
2. The log that was produced after running MalwareBytes' Anti-Malware.
3. The log that was produced after running ESET Online Scanner.
4. An update on how your computer is currently running?
You are doing great!
everytime i restart the laptop, on the startup programs icons (lower right corner, next to the clock) appears an icon from System Configuration Utility
telling me "Blocked Startup Programs" when i click on it, its shows me that malwarebytes is blocked from running… is it because i already have an
antivirus (mcafee) and dont let me use both programs at the same time?? what should i do to make that icon dissapear everytime…
According to the information that I found on the MalwareBytes' Anti-Malware Support Forum this is a known bug that is scheduled to be fixed in the next version.
To fix this issue please do the following:
Back-Up Registry
First, we need to backup your registry:
Please go to Start > Run
Paste in the following line:
regedit /e c:\registrybackup.reg
Click OK.
It won't appear to be doing anything, that's normal.
Your mouse pointer may turn to an hour glass for a minute.
Please continue when it no longer has the hour glass.
Open Notepad
Click Start > Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.
Copy the text inside of the code box, Press Ctrl+C (or right click on the highlighted section and choose 'copy')
Now paste the copied text into the open notepad. Press CTRL+V (or right click and choose 'paste')
Note: There must be NO blank lines in front of the pasted text, but ensure that there is a blank line at the end of the text, otherwise the registry merge will not work.
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Malwarebytes Anti-Malware (reboot)"=-
Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in fixme.reg as the file name, then choose All Files as the save as file type.
Then click the save button.
Once you have clicked the save button, close Notepad.
You should now see a file on your desktop that looks like this:
[external image: Posted Image]
Locate the fixme.reg icon on your desktop and double click it, an information box will pop up asking if you want to merge the information in the file into the registry, click YES.
Once the file has run, the information will have merged with your registry so you can delete fixme.reg from your desktop as you won't be needing it anymore.
As long as the file remains in quarantine it is no longer a threat to your computer and can't do anymore harm.should i put delete to that file or the pc will erradicate the quarantined item by itself ????
Re-Scanning with DDS
Please re-run DDS by sUBs.
Make sure to pay attention to the directions below:
- Disable any script blocking protection (How to Disable your Security Programs)
- Double click DDS icon to run the tool (may take up to 3 minutes to run)
- When done, DDS.txt will open.
- After a few moments, attach.txt will open in a second window.
- Save both reports to your desktop.
- Post the contents of the DDS.txt report in your next reply
- Attach the Attach.txt report to your post by doing the following:
- Under the reply panel is the Attachments Panel
- Browse for the attachment file you want to upload, then click the green Upload button
- Once it has uploaded, click the Manage Current Attachments drop down box
- Click on [external image: Posted Image] to insert the attachment into your post
1. The logs that were produced after running DDS. (DDS.txt and Attach.txt)
2. Any problems you are experiencing with your computer. (If Any)
Note: The DelDomains.inf file will remove ALL entries in the Trusted, Restricted, and Enhanced Security Configuration Zones. Any entries that you had will need to be entered again. You will have to re-immunize with SpywareBlaster, and/or Spybot after doing this, and reinstall IESpyads if you use any of these programs.
below u can find my logs from the re-scan of DDS mate….
i was reading the posts, and i found in the first posts from you, that you told me that we will have to re-immunize with those programs, shall we do this too or we just gonna skip it as well….???
btw no pop-up's during the whole day, pc is running smoothly now…
and hahahahhah (sorry one more thing), i have a question about malwarebytes…:
remember that we fix it with "regedit"?? my question is, that if malwarebytes runs in the background by itself or if it only works when i turn it ON to scann my pc (because i remember that it was being blocked from my startup programs)
again thnx a lot for your help
DDS (Ver_09-10-26.01) - NTFSx86
Run by [removed] at 20:14:44.00 on Mon 11/23/2009
Internet Explorer: 8.0.6001.18828 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1994 [GMT -6:00]
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Fingerprint Reader Suite\upeksvr.exe
C:\Windows\system32\aestsrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Windows\system32\CTsvcCDA.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Windows\system32\taskeng.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Roxio Creator 2009\5.0\CPMonitor.exe
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Latisnere\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p;=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [VolPanel] "c:\program files\creative\sbaudigy\volume panel\VolPanlu.exe" /r
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [PSQLLauncher] "c:\program files\fingerprint reader suite\launcher.exe" /startup
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\11.0\sharedcom\RoxWatchTray11.exe"
mRun: [CPMonitor] "c:\program files\roxio creator 2009\5.0\CPMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\1.0.150\SSScheduler.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth; Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: psfus - c:\windows\system32\psqlpwd.dll
LSA: Notification Packages = scecli psqlpwd
================= FIREFOX ===================
FF - ProfilePath - c:\users\latisn~1\appdata\roaming\mozilla\firefox\profiles\xtqgsnxv.default\
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10607&gct;=&gc;=1&q;=
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-10-28 73728]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-7-24 210216]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2007-10-10 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2008-10-27 7424]
S2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\roxio creator 2009\digital home 11\RoxioUpnpService11.exe [2008-8-13 367088]
S2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\common files\roxio shared\11.0\sharedcom\RoxLiveShare11.exe [2008-8-13 309744]
S2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\common files\roxio shared\11.0\sharedcom\RoxWatch11.exe [2008-8-13 170480]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-7-24 21504]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\roxio creator 2009\digital home 11\RoxioUPnPRenderer11.exe [2008-8-13 313840]
S3 RoxMediaDB11;RoxMediaDB11;c:\program files\common files\roxio shared\11.0\sharedcom\RoxMediaDB11.exe [2008-8-13 1124848]
S4 iaNvStor;Intel® Turbo Memory Controller;c:\windows\system32\drivers\iaNvStor.sys [2008-10-27 209408]
=============== Created Last 30 ================
2009-11-24 01:52:47 307426880 —-a-w- C:\registrybackup.reg
2009-11-21 22:38:08 0 d—–w- c:\programdata\Office Genuine Advantage
2009-11-21 22:11:50 0 d—–w- c:\users\latisn~1\appdata\roaming\Malwarebytes
2009-11-21 22:11:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-21 22:11:45 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 22:11:45 0 d—–w- c:\programdata\Malwarebytes
2009-11-21 22:11:45 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-21 16:28:21 98816 —-a-w- c:\windows\sed.exe
2009-11-21 16:28:21 77312 —-a-w- c:\windows\MBR.exe
2009-11-21 16:28:21 260608 —-a-w- c:\windows\PEV.exe
2009-11-21 16:28:21 161792 —-a-w- c:\windows\SWREG.exe
2009-11-18 17:27:43 0 d—–w- c:\programdata\Citrix
2009-11-18 17:23:48 0 d—–w- c:\program files\Citrix
2009-11-18 17:23:29 61224 —-a-w- c:\users\latisnere\GoToAssistDownloadHelper.exe
2009-11-18 02:03:30 0 d—–w- c:\program files\Windows Portable Devices
2009-11-18 02:03:19 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 02:03:15 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-18 02:00:57 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2009-11-18 02:00:52 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2009-11-18 02:00:52 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2009-11-18 01:57:44 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-11-18 01:57:41 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-18 01:57:41 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-11-18 01:47:58 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2009-11-18 01:47:55 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2009-11-18 01:47:54 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-11-18 01:47:40 2036736 —-a-w- c:\windows\system32\win32k.sys
2009-11-18 01:47:26 310784 —-a-w- c:\windows\system32\unregmp2.exe
2009-11-18 01:47:24 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-11-18 01:44:17 355328 —-a-w- c:\windows\system32\WSDApi.dll
2009-11-18 01:38:43 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-18 01:27:34 0 d—–w- c:\users\latisn~1\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-11-18 01:23:11 0 d—–w- c:\programdata\Adobe
2009-11-18 01:12:45 0 d—–w- c:\programdata\McAfee Security Scan
2009-11-18 01:12:34 0 d—–w- c:\program files\McAfee Security Scan
2009-11-18 01:11:07 0 d—–w- c:\programdata\NOS
2009-11-10 07:10:39 3426072 —-a-w- c:\windows\system32\d3dx9_32.dll
2009-11-10 07:09:06 0 d—–w- c:\program files\Microsoft
2009-11-08 01:28:14 0 d—–w- c:\users\latisn~1\appdata\roaming\Intel
2009-11-02 09:13:09 0 d—–w- c:\users\latisn~1\appdata\roaming\uTorrent
2009-11-02 08:46:21 0 d—–w- c:\program files\WeFi
2009-11-02 08:44:51 0 d—–w- c:\program files\Vuze
2009-11-01 22:43:16 0 d—–w- c:\program files\abgx360
2009-10-27 03:16:41 2421760 —-a-w- c:\windows\system32\wucltux.dll
2009-10-27 03:16:15 87552 —-a-w- c:\windows\system32\wudriver.dll
2009-10-27 03:16:09 33792 —-a-w- c:\windows\system32\wuapp.exe
2009-10-27 03:16:09 171608 —-a-w- c:\windows\system32\wuwebv.dll
==================== Find3M ====================
2009-11-24 02:04:52 119887 —-a-w- c:\programdata\nvModes.dat
2009-11-18 02:03:24 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 02:03:24 51200 —-a-w- c:\windows\inf\infpub.dat
2009-11-18 02:03:24 143360 —-a-w- c:\windows\inf\infstrng.dat
2009-11-18 02:03:24 143360 —-a-w- c:\windows\inf\infstor.dat
2009-10-01 01:02:17 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02:05 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02:04 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02:02 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02:00 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01:59 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01:59 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01:56 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01:56 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01:56 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01:56 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01:54 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01:54 40448 —-a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01:50 226816 —-a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01:49 61952 —-a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01:49 33280 —-a-w- c:\windows\system32\WpdConns.dll
2009-09-25 02:10:10 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07:08 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04:32 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49:22 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48:08 351232 —-a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38:29 847360 —-a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36:13 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35:31 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33:25 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33:15 829440 —-a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33:01 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32:59 252928 —-a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31:53 519680 —-a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31:26 486912 —-a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31:21 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31:19 218112 —-a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31:16 1030144 —-a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31:15 828928 —-a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30:23 481792 —-a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30:23 190464 —-a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27:04 793088 —-a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27:04 37888 —-a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27:04 1064448 —-a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54:55 258048 —-a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54:53 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54:52 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-16 21:14:07 56 —ha-w- c:\programdata\ezsidmv.dat
2009-09-10 16:48:01 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-04 11:41:59 60928 —-a-w- c:\windows\system32\msasn1.dll
2009-08-27 05:22:28 916480 —-a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17:43 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17:43 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42:29 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-07-24 07:33:44 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-10-27 20:39:41 8192 –sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 20:15:12.57 ===============
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI