PcRebel
Topic Starter
I'm unsure of the extent of my problems, but there has to be an infection(s) somewhere. PC been running super slow for a few weeks now and nothing I do helps more than a day or so at a time. My high speed dsl connection is slower than dial up 99% of the time. I scanned a couple of days ago with Trend Micro and Malwarebytes and all came up empty. I also use Spywareblaster and I ran Cleanup. Until tonite, nothing has been found since 12/16/09 when Malwarebytes found 1 file and 4 registry keys infected with Trojan.Buzus. I disabled windows firewall and installed Online Armour AV & Firewall a couple of days ago and it said the program would start when I restarted my computer, so I did, and every time it got to the XP welcome screen it would restart itself. I went into safe mode to msconfig and unchecked it from the startup tab it and was able to get back to my desktop. I went back to enable windows firewall again until I get this staightened out but somehow it was already back on and I don't have a clue how that happened. Last night, pc was barely puttin' along and on the verge of freezing so I checked Task Manager and CPU was at 100% again so restarted and it took a good 5-6 minutes to load. I then I updated my Revo Uninstaller and began uninstalling a game (Wizard 101) and Revo froze for like 10 minutes. When it started working again there was a severe malfunction. It said it found 10,900 left over files! Good thing I noticed it before clicking "select all + delete" because my entire C:\Games folder would have been history. I've been using Revo Uninstaller for a long time and have never had a problem with it. I checked Task Manager again and CPU was at 100% again after just restarting. As a last note, I ran Trend Micro HJT and had it analyzed at www.hijackthis.de and it recommended putting checkmarks by 3 toolbars (2 Ask and a disabled Reganam) and 1 URLSearchHook so HJT could fix them, but I didn't because I'd prefer a real person helping me. Sorry for the long post and thanks in advance for any help you can give me. Will wait to hear back from someone before doing anything else.
Here's my mbam log:
Malwarebytes' Anti-Malware 1.44
Database version: 3698
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/6/2010 7:11:44 PM
mbam-log-2010-02-06 (19-11-44).txt
Scan type: Quick Scan
Objects scanned: 109206
Time elapsed: 11 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) ->
Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Here is the GMER Report:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-06 22:05:06
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver:
C:\DOCUME~1\DAWNWA~1\LOCALS~1\Temp\kwldipog.sys
—- System - GMER 1.0.15 —-
SSDT SnopFree.sys ZwCreateProcessEx [0xF88B39E4]
SSDT SnopFree.sys ZwTerminateProcess [0xF88B39F4]
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 hotcore3.sys (A part
of Paragon System Utilities/Paragon Software Group)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 hotcore3.sys (A part
of Paragon System Utilities/Paragon Software Group)
—- EOF - GMER 1.0.15 —-
Here is the DDS Log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:38:46.37 on Sat 02/06/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.205 [GMT
-5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Documents and Settings\Dawn Walker\Application
Data\mjusbsp\magicJack.exe
C:\Documents and Settings\Dawn Walker\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://google.com/
uSearch Page = hxxp://google.com/
uSearchURL,(Default) =
hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101703&gct=&gc=1&q=%s
uURLSearchHooks: DefaultSearchHook Class:
{c94e154b-1459-4a47-966b-4b843befc7db} -
BHO: Java™ Plug-In SSV Helper:
{761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program
files\java\jre6\bin\ssv.dll
BHO: {db9d7a78-a76c-4bf2-97c6-258925ee1542} - No File
BHO: Java™ Plug-In 2 SSV Helper:
{dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\java\jre6\bin\jp2ssv.dll
TB: {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} - No File
uRun: [cdloader] "c:\documents and settings\dawn walker\application
data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [AOL Fast Start] "c:\program files\aol 9.1\AOL.EXE" -b
mRun: [SnoopFreeUI] SnoopFreeUI.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xport to Microsoft Excel -
c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program
files\messenger\msmsgs.exe
Trusted Zone: 0.0.0.0
DPF: Microsoft XML Parser for Java -
file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} -
hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} -
hxxp://aolsvc.aol.com/onlinegames/free-trial-emerald-city-confidential/Emerald
CityConfidential_Web.1.0.0.9.cab
DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} -
hxxp://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} -
hxxp://cdn.ll.neoedge.com/webgames/MysteryofSharkIsland/MysteryOfSharkI
slandWeb.1.0.0.8.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} -
hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} -
hxxp://www.worldwinner.com/games/v63/bjattack/bja.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} -
hxxp://aolsvc.aol.com/onlinegames/free-trial-rainforest-adventure/gamehousepl
ayer.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} -
hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} -
hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} -
hxxp://www.worldwinner.com/games/v68/clue/clue.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} -
hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} -
hxxp://www.worldwinner.com/games/v67/swapit/swapit.cab
DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} -
hxxp://www.worldwinner.com/games/v46/grandslam/grandslamtrivia.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} -
hxxp://www.worldwinner.com/games/v49/familyfeud/familyfeud.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} -
hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
hxxp://games.pogo.com/online2/pogo/bookworm_adventures/popcaploader_v10.
cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program
files\common files\microsoft shared\web folders\PKMCDO.DLL
============= SERVICES / DRIVERS ===============
R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys
[2009-4-8 40560]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-4-6
28544]
R0 SnoopFree;SnoopFree Driver;c:\windows\system32\drivers\SnopFree.sys
[2009-7-9 9472]
R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2001-8-23
14336]
R2 SnoopFreeSvc;Snoop Free Service;System32\SnoopFreeSvc.exe –>
System32\SnoopFreeSvc.exe [?]
S3 BCASPROT;Advanced System Protector;c:\program files\systweak\advanced
system protector\sasprot32.sys [2009-5-4 6656]
S3 m4cxwxp;NDIS5.1 Miniport Driver for D-Link DGE-530T Gigabit Ethernet
Adapter;c:\windows\system32\drivers\m4cxwxp.sys –>
c:\windows\system32\drivers\m4cxwxp.sys [?]
S3 motccgp;Motorola USB Composite Device
Driver;c:\windows\system32\drivers\motccgp.sys [2009-12-25 19712]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys
[2009-12-25 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys
[2009-12-25 42752]
S3 motport;Motorola USB Diagnostic
Port;c:\windows\system32\drivers\motport.sys [2009-12-25 23680]
S4 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs
[2001-8-23 14336]
============== File Associations ===============
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
=============== Created Last 30 ================
2010-02-04 23:18 –d—– c:\program files\Trend Micro
2010-02-04 01:09 –d—–
c:\docume~1\dawnwa~1\applic~1\OnlineArmor
2010-02-04 01:09 –d—–
c:\docume~1\alluse~1\applic~1\OnlineArmor
2010-02-04 00:49 223,312 a——-
c:\windows\system32\drivers\OADriver.sys
2010-02-04 00:49 29,776 a——-
c:\windows\system32\drivers\OAnet.sys
2010-02-04 00:49 24,656 a——-
c:\windows\system32\drivers\OAmon.sys
2010-02-04 00:49 –d—– c:\program files\Tall Emu
2010-02-03 23:44 11,264 a–sh— c:\windows\Thumbs.db
2010-02-03 23:44 4,608 a–sh— c:\windows\system32\Thumbs.db
2010-01-29 04:25 53,680 a——-
c:\docume~1\dawnwa~1\applic~1\GDIPFONTCACHEV1.DAT
2010-01-25 23:20 –d—–
c:\docume~1\alluse~1\applic~1\GameHouse
2010-01-23 21:16 –d—– c:\docume~1\alluse~1\applic~1\PopCap
2010-01-19 18:12 –d—–
c:\docume~1\dawnwa~1\applic~1\VSRevoGroup
2010-01-19 13:49 0 a—h—
c:\windows\system32\drivers\Msft_Kernel_motport_01007.Wdf
==================== Find3M ====================
2010-01-07 16:07 38,224 a——-
c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 19,160 a——-
c:\windows\system32\drivers\mbam.sys
2009-12-25 21:40 0 a—h—
c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
2009-12-25 21:40 0 a—h—
c:\windows\system32\drivers\Msft_Kernel_motccgp_01007.Wdf
2009-12-25 20:08 0 a—h—
c:\windows\system32\drivers\Msft_Kernel_motmodem_01007.Wdf
2009-12-25 20:08 0 a—h—
c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wd
f
2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-16 18:03 216,064 a——- c:\windows\iun3405.exe
2009-12-02 05:12 4,254,224 a——- c:\windows\system32\qtp-mt334.dll
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-11-13 19:49 129,784 ——– c:\windows\system32\pxafs.dll
2009-11-13 19:49 120,056 ——– c:\windows\system32\pxcpyi64.exe
2009-11-13 19:49 118,520 ——– c:\windows\system32\pxinsi64.exe
2009-11-13 19:47 90,112 a——- c:\windows\system32\dpl100.dll
2009-11-13 19:47 856,064 a——- c:\windows\system32\divx_xx0c.dll
2009-11-13 19:47 856,064 a——- c:\windows\system32\divx_xx07.dll
2009-11-13 19:47 847,872 a——- c:\windows\system32\divx_xx0a.dll
2009-11-13 19:47 843,776 a——- c:\windows\system32\divx_xx16.dll
2009-11-13 19:47 839,680 a——- c:\windows\system32\divx_xx11.dll
2009-11-13 19:47 696,320 a——- c:\windows\system32\DivX.dll
2009-10-21 15:40 8,628 a—h— c:\program files\GMOUSE.GID
2009-10-21 15:34 12,800 a–sh— c:\program files\Thumbs.db
============= FINISH: 22:39:44.91 ===============
Here's my mbam log:
Malwarebytes' Anti-Malware 1.44
Database version: 3698
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/6/2010 7:11:44 PM
mbam-log-2010-02-06 (19-11-44).txt
Scan type: Quick Scan
Objects scanned: 109206
Time elapsed: 11 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) ->
Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Here is the GMER Report:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-06 22:05:06
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver:
C:\DOCUME~1\DAWNWA~1\LOCALS~1\Temp\kwldipog.sys
—- System - GMER 1.0.15 —-
SSDT SnopFree.sys ZwCreateProcessEx [0xF88B39E4]
SSDT SnopFree.sys ZwTerminateProcess [0xF88B39F4]
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 hotcore3.sys (A part
of Paragon System Utilities/Paragon Software Group)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 hotcore3.sys (A part
of Paragon System Utilities/Paragon Software Group)
—- EOF - GMER 1.0.15 —-
Here is the DDS Log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:38:46.37 on Sat 02/06/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.205 [GMT
-5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Documents and Settings\Dawn Walker\Application
Data\mjusbsp\magicJack.exe
C:\Documents and Settings\Dawn Walker\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://google.com/
uSearch Page = hxxp://google.com/
uSearchURL,(Default) =
hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101703&gct=&gc=1&q=%s
uURLSearchHooks: DefaultSearchHook Class:
{c94e154b-1459-4a47-966b-4b843befc7db} -
BHO: Java™ Plug-In SSV Helper:
{761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program
files\java\jre6\bin\ssv.dll
BHO: {db9d7a78-a76c-4bf2-97c6-258925ee1542} - No File
BHO: Java™ Plug-In 2 SSV Helper:
{dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\java\jre6\bin\jp2ssv.dll
TB: {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} - No File
uRun: [cdloader] "c:\documents and settings\dawn walker\application
data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [AOL Fast Start] "c:\program files\aol 9.1\AOL.EXE" -b
mRun: [SnoopFreeUI] SnoopFreeUI.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xport to Microsoft Excel -
c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program
files\messenger\msmsgs.exe
Trusted Zone: 0.0.0.0
DPF: Microsoft XML Parser for Java -
file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} -
hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {18F616CD-4B28-4C47-815A-560AC6A33C8D} -
hxxp://aolsvc.aol.com/onlinegames/free-trial-emerald-city-confidential/Emerald
CityConfidential_Web.1.0.0.9.cab
DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} -
hxxp://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} -
hxxp://cdn.ll.neoedge.com/webgames/MysteryofSharkIsland/MysteryOfSharkI
slandWeb.1.0.0.8.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} -
hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} -
hxxp://www.worldwinner.com/games/v63/bjattack/bja.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} -
hxxp://aolsvc.aol.com/onlinegames/free-trial-rainforest-adventure/gamehousepl
ayer.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} -
hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} -
hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} -
hxxp://www.worldwinner.com/games/v68/clue/clue.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} -
hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} -
hxxp://www.worldwinner.com/games/v67/swapit/swapit.cab
DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} -
hxxp://www.worldwinner.com/games/v46/grandslam/grandslamtrivia.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} -
hxxp://www.worldwinner.com/games/v49/familyfeud/familyfeud.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} -
hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
hxxp://games.pogo.com/online2/pogo/bookworm_adventures/popcaploader_v10.
cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program
files\common files\microsoft shared\web folders\PKMCDO.DLL
============= SERVICES / DRIVERS ===============
R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys
[2009-4-8 40560]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-4-6
28544]
R0 SnoopFree;SnoopFree Driver;c:\windows\system32\drivers\SnopFree.sys
[2009-7-9 9472]
R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2001-8-23
14336]
R2 SnoopFreeSvc;Snoop Free Service;System32\SnoopFreeSvc.exe –>
System32\SnoopFreeSvc.exe [?]
S3 BCASPROT;Advanced System Protector;c:\program files\systweak\advanced
system protector\sasprot32.sys [2009-5-4 6656]
S3 m4cxwxp;NDIS5.1 Miniport Driver for D-Link DGE-530T Gigabit Ethernet
Adapter;c:\windows\system32\drivers\m4cxwxp.sys –>
c:\windows\system32\drivers\m4cxwxp.sys [?]
S3 motccgp;Motorola USB Composite Device
Driver;c:\windows\system32\drivers\motccgp.sys [2009-12-25 19712]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys
[2009-12-25 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys
[2009-12-25 42752]
S3 motport;Motorola USB Diagnostic
Port;c:\windows\system32\drivers\motport.sys [2009-12-25 23680]
S4 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs
[2001-8-23 14336]
============== File Associations ===============
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
=============== Created Last 30 ================
2010-02-04 23:18 –d—– c:\program files\Trend Micro
2010-02-04 01:09 –d—–
c:\docume~1\dawnwa~1\applic~1\OnlineArmor
2010-02-04 01:09 –d—–
c:\docume~1\alluse~1\applic~1\OnlineArmor
2010-02-04 00:49 223,312 a——-
c:\windows\system32\drivers\OADriver.sys
2010-02-04 00:49 29,776 a——-
c:\windows\system32\drivers\OAnet.sys
2010-02-04 00:49 24,656 a——-
c:\windows\system32\drivers\OAmon.sys
2010-02-04 00:49 –d—– c:\program files\Tall Emu
2010-02-03 23:44 11,264 a–sh— c:\windows\Thumbs.db
2010-02-03 23:44 4,608 a–sh— c:\windows\system32\Thumbs.db
2010-01-29 04:25 53,680 a——-
c:\docume~1\dawnwa~1\applic~1\GDIPFONTCACHEV1.DAT
2010-01-25 23:20 –d—–
c:\docume~1\alluse~1\applic~1\GameHouse
2010-01-23 21:16 –d—– c:\docume~1\alluse~1\applic~1\PopCap
2010-01-19 18:12 –d—–
c:\docume~1\dawnwa~1\applic~1\VSRevoGroup
2010-01-19 13:49 0 a—h—
c:\windows\system32\drivers\Msft_Kernel_motport_01007.Wdf
==================== Find3M ====================
2010-01-07 16:07 38,224 a——-
c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 16:07 19,160 a——-
c:\windows\system32\drivers\mbam.sys
2009-12-25 21:40 0 a—h—
c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01007.Wdf
2009-12-25 21:40 0 a—h—
c:\windows\system32\drivers\Msft_Kernel_motccgp_01007.Wdf
2009-12-25 20:08 0 a—h—
c:\windows\system32\drivers\Msft_Kernel_motmodem_01007.Wdf
2009-12-25 20:08 0 a—h—
c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wd
f
2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-16 18:03 216,064 a——- c:\windows\iun3405.exe
2009-12-02 05:12 4,254,224 a——- c:\windows\system32\qtp-mt334.dll
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-11-13 19:49 129,784 ——– c:\windows\system32\pxafs.dll
2009-11-13 19:49 120,056 ——– c:\windows\system32\pxcpyi64.exe
2009-11-13 19:49 118,520 ——– c:\windows\system32\pxinsi64.exe
2009-11-13 19:47 90,112 a——- c:\windows\system32\dpl100.dll
2009-11-13 19:47 856,064 a——- c:\windows\system32\divx_xx0c.dll
2009-11-13 19:47 856,064 a——- c:\windows\system32\divx_xx07.dll
2009-11-13 19:47 847,872 a——- c:\windows\system32\divx_xx0a.dll
2009-11-13 19:47 843,776 a——- c:\windows\system32\divx_xx16.dll
2009-11-13 19:47 839,680 a——- c:\windows\system32\divx_xx11.dll
2009-11-13 19:47 696,320 a——- c:\windows\system32\DivX.dll
2009-10-21 15:40 8,628 a—h— c:\program files\GMOUSE.GID
2009-10-21 15:34 12,800 a–sh— c:\program files\Thumbs.db
============= FINISH: 22:39:44.91 ===============